2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48440MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-47065MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit...
CVE-2023-47064MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-33217HIGH7.5 By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent ...
CVE-2023-6838MEDIUM6.1Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be pe...
CVE-2023-6837HIGH8.2Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order...
CVE-2023-6836HIGH7.5Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely ava...
CVE-2023-6835MEDIUM5.3Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum featu...
CVE-2023-48395MEDIUM6.5Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special f...
CVE-2023-48394HIGH8.8Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file wit...
CVE-2023-48393MEDIUM4.3Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial...
CVE-2023-48392CRITICAL9.8Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un...
CVE-2023-48390CRITICAL9.8Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerabi...
CVE-2023-48389HIGH7.5Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated rem...
CVE-2023-48388CRITICAL9.8Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerab...
CVE-2023-48387HIGH8.8TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registr...
CVE-2023-48384CRITICAL9.8ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. A...
CVE-2023-48382MEDIUM6.5Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail de...
CVE-2023-48381MEDIUM6.5Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special...
CVE-2023-48380HIGH8Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a...
CVE-2023-46279CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are r...
CVE-2023-29234CRITICAL9.8A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 thro...
CVE-2023-6827HIGH8.8The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val...
CVE-2023-6826HIGH7.2The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '...
CVE-2023-48379MEDIUM5.3Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter withi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now