2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49624 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter ... |
| CVE-2023-49622 | CRITICAL | 9.8 | 0.7% | Jan 4, 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' paramete... |
| CVE-2023-6992 | MEDIUM | 5.5 | 0.2% | Jan 4, 2024 | Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algori... |
| CVE-2023-7044 | MEDIUM | 5.4 | 0.4% | Jan 4, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2023-6944 | MEDIUM | 5.7 | 0.6% | Jan 4, 2024 | A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the fron... |
| CVE-2023-50630 | MEDIUM | 6.1 | 0.5% | Jan 4, 2024 | Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-50082 | HIGH | 7.5 | 0.6% | Jan 4, 2024 | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive in... |
| CVE-2023-41784 | MEDIUM | 5.5 | 0.2% | Jan 4, 2024 | Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro |
| CVE-2023-52322 | MEDIUM | 6.1 | 0.4% | Jan 4, 2024 | ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not... |
| CVE-2023-29962 | MEDIUM | 6.5 | 0.7% | Jan 4, 2024 | S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability. |
| CVE-2023-6738 | MEDIUM | 5.4 | 0.4% | Jan 4, 2024 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2023-6733 | MEDIUM | 6.5 | 0.4% | Jan 4, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2023-6498 | MEDIUM | 4.8 | 0.3% | Jan 4, 2024 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2023-5138 | MEDIUM | 6.8 | 0.3% | Jan 3, 2024 | Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, ex... |
| CVE-2023-50256 | HIGH | 7.5 | 0.7% | Jan 3, 2024 | Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registratio... |
| CVE-2023-52141 | — | — | — | Jan 3, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po... |
| CVE-2023-52140 | — | — | — | Jan 3, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po... |
| CVE-2023-6540 | HIGH | 7.5 | 0.5% | Jan 3, 2024 | A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an att... |
| CVE-2023-6338 | HIGH | 7.8 | 0.2% | Jan 3, 2024 | Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an a... |
| CVE-2023-49442 | CRITICAL | 9.8 | 38.5% | Jan 3, 2024 | Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary ... |
| CVE-2023-5881 | HIGH | 8.2 | 0.6% | Jan 3, 2024 | Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Gar... |
| CVE-2023-5880 | HIGH | 8.8 | 0.6% | Jan 3, 2024 | When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode t... |
| CVE-2023-5879 | MEDIUM | 6.8 | 0.4% | Jan 3, 2024 | Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Applicat... |
| CVE-2023-50090 | CRITICAL | 9.8 | 0.8% | Jan 3, 2024 | Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write a... |
| CVE-2023-46929 | HIGH | 7.5 | 0.8% | Jan 3, 2024 | An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tool... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now