2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53926 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers ... |
| CVE-2023-53923 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrati... |
| CVE-2023-53922 | CRITICAL | 9.8 | 0.9% | Dec 17, 2025 | TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthe... |
| CVE-2023-53921 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to... |
| CVE-2023-53914 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user... |
| CVE-2023-53899 | CRITICAL | 9.8 | 0.5% | Dec 16, 2025 | PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in... |
| CVE-2023-53895 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts... |
| CVE-2023-53894 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type com... |
| CVE-2023-53877 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to ma... |
| CVE-2023-53874 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows att... |
| CVE-2023-53872 | CRITICAL | 9.3 | 1.1% | Dec 15, 2025 | Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execu... |
| CVE-2023-53871 | CRITICAL | 9.8 | 0.5% | Dec 15, 2025 | Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PH... |
| CVE-2023-53740 | CRITICAL | 9.8 | 0.8% | Dec 10, 2025 | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password ... |
| CVE-2023-53774 | CRITICAL | 9.8 | 0.8% | Dec 9, 2025 | MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to se... |
| CVE-2023-53771 | CRITICAL | 9.8 | 0.9% | Dec 9, 2025 | MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root passwor... |
| CVE-2023-53739 | CRITICAL | 9.9 | 0.5% | Dec 9, 2025 | Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers t... |
| CVE-2023-53794 | CRITICAL | 9.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: fix session state check in reconnect to avoid... |
| CVE-2023-53769 | CRITICAL | 9.3 | 0.1% | Dec 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The en... |
| CVE-2023-53751 | CRITICAL | 9.8 | 0.2% | Dec 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Serv... |
| CVE-2023-7330 | CRITICAL | 9.3 | 0.5% | Nov 24, 2025 | Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php.... |
| CVE-2023-7325 | CRITICAL | 9.3 | 0.4% | Oct 30, 2025 | Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request fo... |
| CVE-2023-28815 | CRITICAL | 9.8 | 1.5% | Oct 17, 2025 | Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command in... |
| CVE-2023-28814 | CRITICAL | 9.8 | 0.5% | Oct 17, 2025 | Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the impro... |
| CVE-2023-7311 | CRITICAL | 9.3 | 1.9% | Oct 15, 2025 | BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoi... |
| CVE-2023-7305 | CRITICAL | 9.2 | 0.5% | Oct 15, 2025 | SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Und... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now