2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41543 | CRITICAL | 9.8 | 0.9% | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive in... |
| CVE-2023-41542 | CRITICAL | 9.8 | 0.9% | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensi... |
| CVE-2023-50559 | MEDIUM | 5.5 | 0.2% | Dec 30, 2023 | An issue was discovered in XiangShan v2.1, allows local attackers to obtain sensitive information via the L1D cache. |
| CVE-2023-52240 | MEDIUM | 6.1 | 0.5% | Dec 29, 2023 | The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Bindi... |
| CVE-2023-50071 | HIGH | 8.8 | 13.8% | Dec 29, 2023 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?acti... |
| CVE-2023-50070 | HIGH | 8.8 | 0.8% | Dec 29, 2023 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?acti... |
| CVE-2023-50069 | MEDIUM | 6.1 | 0.4% | Dec 29, 2023 | WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the reco... |
| CVE-2023-50035 | CRITICAL | 9.8 | 0.6% | Dec 29, 2023 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is dire... |
| CVE-2023-7171 | MEDIUM | 4.8 | 0.5% | Dec 29, 2023 | A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability... |
| CVE-2023-52139 | CRITICAL | 9.6 | 0.5% | Dec 29, 2023 | Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endp... |
| CVE-2023-52137 | HIGH | 8.8 | 2.6% | Dec 29, 2023 | The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command in... |
| CVE-2023-51663 | MEDIUM | 5.3 | 0.4% | Dec 29, 2023 | Hail is an open-source, general-purpose, Python-based data analysis tool with additional data types and methods for work... |
| CVE-2023-51688 | HIGH | 7.5 | 0.5% | Dec 29, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin f... |
| CVE-2023-51687 | HIGH | 7.5 | 0.5% | Dec 29, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue ... |
| CVE-2023-51527 | HIGH | 7.5 | 0.5% | Dec 29, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Senol Sahin AI Power: Complete AI Pack – Pow... |
| CVE-2023-51517 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affect... |
| CVE-2023-50572 | MEDIUM | 5.5 | 0.3% | Dec 29, 2023 | An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) er... |
| CVE-2023-50571 | HIGH | 7.8 | 0.4% | Dec 29, 2023 | easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule. |
| CVE-2023-50570 | MEDIUM | 5.5 | 0.3% | Dec 29, 2023 | An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because ... |
| CVE-2023-4675 | CRITICAL | 9.8 | 0.5% | Dec 29, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Tec... |
| CVE-2023-4674 | — | — | 0.3% | Dec 29, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Te... |
| CVE-2023-4541 | CRITICAL | 9.8 | 0.5% | Dec 29, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admi... |
| CVE-2023-47804 | HIGH | 8.8 | 2.7% | Dec 29, 2023 | Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar... |
| CVE-2023-51675 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, U... |
| CVE-2023-51475 | CRITICAL | 9.8 | 0.6% | Dec 29, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM S... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now