2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52218 | CRITICAL | 9.8 | 0.6% | Jan 8, 2024 | Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Wo... |
| CVE-2023-52215 | CRITICAL | 9.8 | 0.6% | Jan 8, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple... |
| CVE-2023-6921 | CRITICAL | 9.1 | 0.7% | Jan 8, 2024 | Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modi... |
| CVE-2023-29050 | CRITICAL | 9.6 | 1.7% | Jan 8, 2024 | The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac... |
| CVE-2023-50948 | CRITICAL | 9.8 | 0.5% | Jan 8, 2024 | IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, whi... |
| CVE-2023-7212 | CRITICAL | 9.8 | 0.6% | Jan 7, 2024 | A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the f... |
| CVE-2023-7210 | CRITICAL | 9.8 | 1.0% | Jan 7, 2024 | A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of th... |
| CVE-2023-7208 | CRITICAL | 9.8 | 1.7% | Jan 7, 2024 | A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects... |
| CVE-2023-46953 | CRITICAL | 9.8 | 0.8% | Jan 6, 2024 | SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in... |
| CVE-2023-51673 | CRITICAL | 9.8 | 0.2% | Jan 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaura... |
| CVE-2023-50027 | CRITICAL | 9.8 | 0.7% | Jan 5, 2024 | SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allow... |
| CVE-2023-51502 | CRITICAL | 9.8 | 0.6% | Jan 5, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This is... |
| CVE-2023-51277 | CRITICAL | 9.8 | 1.1% | Jan 5, 2024 | nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds. |
| CVE-2023-51812 | CRITICAL | 9.8 | 1.1% | Jan 4, 2024 | Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /... |
| CVE-2023-51154 | CRITICAL | 9.8 | 0.6% | Jan 4, 2024 | Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsContr... |
| CVE-2023-50867 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of... |
| CVE-2023-50866 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of... |
| CVE-2023-50865 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the... |
| CVE-2023-50864 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of ... |
| CVE-2023-50863 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' paramet... |
| CVE-2023-50862 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' paramet... |
| CVE-2023-50753 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parame... |
| CVE-2023-50752 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' paramet... |
| CVE-2023-50743 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parame... |
| CVE-2023-49666 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' par... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now