2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-4140HIGH8.8The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including...
CVE-2023-4139HIGH7.5The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing...
CVE-2023-38708HIGH8.8Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path ...
CVE-2023-30146HIGH7.5Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy o...
CVE-2023-36135HIGH7.5User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, whe...
CVE-2023-30297HIGH7An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code v...
CVE-2023-0525HIGH7.5Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000...
CVE-2023-38952HIGH7.5Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due ...
CVE-2023-38950HIGH7.5A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit...
CVE-2023-38949HIGH7.5An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrato...
CVE-2023-37498HIGH8.8A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It...
CVE-2023-37497HIGH8.8The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated ...
CVE-2023-20216HIGH7.8A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica...
CVE-2023-39121HIGH7.2emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
CVE-2023-0956HIGH7.5 External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without ...
CVE-2023-35081HIGH7.2A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) a...
CVE-2023-32764HIGH7.8Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
CVE-2023-38948HIGH7.2An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers t...
CVE-2023-38947HIGH7.2An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to ex...
CVE-2023-33366HIGH8.8A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbit...
CVE-2023-33365HIGH7.5A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch...
CVE-2023-33364HIGH8.8An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to exe...
CVE-2023-33363HIGH7.5An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to a...
CVE-2023-36299HIGH8.8A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and opt...
CVE-2023-36298HIGH8.8DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now