2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41543CRITICAL9.8SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive in...
CVE-2023-41542CRITICAL9.8SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensi...
CVE-2023-50559MEDIUM5.5An issue was discovered in XiangShan v2.1, allows local attackers to obtain sensitive information via the L1D cache.
CVE-2023-52240MEDIUM6.1The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Bindi...
CVE-2023-50071HIGH8.8Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?acti...
CVE-2023-50070HIGH8.8Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?acti...
CVE-2023-50069MEDIUM6.1WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the reco...
CVE-2023-50035CRITICAL9.8PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is dire...
CVE-2023-7171MEDIUM4.8A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability...
CVE-2023-52139CRITICAL9.6Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endp...
CVE-2023-52137HIGH8.8The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command in...
CVE-2023-51663MEDIUM5.3Hail is an open-source, general-purpose, Python-based data analysis tool with additional data types and methods for work...
CVE-2023-51688HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin f...
CVE-2023-51687HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue ...
CVE-2023-51527HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Senol Sahin AI Power: Complete AI Pack – Pow...
CVE-2023-51517MEDIUM5.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affect...
CVE-2023-50572MEDIUM5.5An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) er...
CVE-2023-50571HIGH7.8easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
CVE-2023-50570MEDIUM5.5An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because ...
CVE-2023-4675CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Tec...
CVE-2023-4674Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Te...
CVE-2023-4541CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admi...
CVE-2023-47804HIGH8.8Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar...
CVE-2023-51675MEDIUM5.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, U...
CVE-2023-51475CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM S...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now