2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40814MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
CVE-2023-40813MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.
CVE-2023-40812MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
CVE-2023-40810MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
CVE-2023-40809MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
CVE-2023-6187HIGH8.8The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type vali...
CVE-2023-4214CRITICAL9.8The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5...
CVE-2023-48017HIGH8.8Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Managemen...
CVE-2023-48028CRITICAL9.8kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an at...
CVE-2023-46402HIGH7.5git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.
CVE-2023-44796MEDIUM5.4Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate ...
CVE-2023-43177CRITICAL9.8CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes...
CVE-2023-48294MEDIUM4.3LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2023-48238HIGH7.5joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL...
CVE-2023-46745HIGH7.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2023-48295MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2023-6188CRITICAL9.8A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown ...
CVE-2023-48185HIGH7.5Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive inf...
CVE-2023-6179HIGH7.8Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable...
CVE-2023-48025HIGH8.1Liblisp through commit 4c65969 was discovered to contain a out-of-bounds-read vulnerability in unsigned get_length(lisp_...
CVE-2023-48024MEDIUM6.5Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_...
CVE-2023-44355MEDIUM4.3Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu...
CVE-2023-44353CRITICAL9.8Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted...
CVE-2023-44352MEDIUM6.1Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scriptin...
CVE-2023-44351CRITICAL9.8Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now