2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41804 | MEDIUM | 5.4 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver B... |
| CVE-2023-50164 | CRITICAL | 9.8 | 80.8% | Dec 7, 2023 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to up... |
| CVE-2023-48861 | HIGH | 7.8 | 0.3% | Dec 7, 2023 | DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitra... |
| CVE-2023-48860 | CRITICAL | 9.8 | 1.4% | Dec 7, 2023 | TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attac... |
| CVE-2023-49225 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If t... |
| CVE-2023-48841 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
| CVE-2023-48840 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. |
| CVE-2023-48839 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_ap... |
| CVE-2023-48838 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code. |
| CVE-2023-48837 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. |
| CVE-2023-48836 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_ke... |
| CVE-2023-48835 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
| CVE-2023-48834 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. |
| CVE-2023-48833 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaus... |
| CVE-2023-48831 | HIGH | 7.5 | 1.2% | Dec 7, 2023 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exha... |
| CVE-2023-48830 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. |
| CVE-2023-48828 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_... |
| CVE-2023-48827 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin... |
| CVE-2023-48826 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. |
| CVE-2023-48825 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Cod... |
| CVE-2023-48824 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or key... |
| CVE-2023-48823 | CRITICAL | 9.8 | 1.1% | Dec 7, 2023 | A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker t... |
| CVE-2023-48208 | MEDIUM | 6.1 | 0.5% | Dec 7, 2023 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via th... |
| CVE-2023-48207 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. |
| CVE-2023-48206 | MEDIUM | 6.1 | 0.6% | Dec 7, 2023 | A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to injec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now