2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47445CRITICAL9.8Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
CVE-2023-41597MEDIUM6.1EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/t...
CVE-2023-40923HIGH8.8MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php vi...
CVE-2023-6032MEDIUM5.3 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul...
CVE-2023-5987MEDIUM6.1 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could ca...
CVE-2023-5986MEDIUM6.1 A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading...
CVE-2023-5985MEDIUM4.8 A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise...
CVE-2023-5984MEDIUM4.9 A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be upload...
CVE-2023-47678CRITICAL9.1An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are n...
CVE-2023-47309MEDIUM5.4Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::...
CVE-2023-47308CRITICAL9.8In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design fo...
CVE-2023-43979CRITICAL9.8ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogMo...
CVE-2023-46121LOW3.7yt-dlp is a youtube-dl fork with additional features and fixes. The Generic Extractor in yt-dlp is vulnerable to an atta...
CVE-2023-43591HIGH7.8Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct ...
CVE-2023-43590HIGH7.8Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation o...
CVE-2023-43588MEDIUM6.5Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disc...
CVE-2023-43582HIGH8.8Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via netwo...
CVE-2023-41718HIGH7.8When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the aff...
CVE-2023-39337CRITICAL9.1A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled...
CVE-2023-39335CRITICAL9.8A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated...
CVE-2023-38544MEDIUM5.5A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. ...
CVE-2023-38543HIGH7.8A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally au...
CVE-2023-38043HIGH7.8A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally au...
CVE-2023-35080HIGH7.8A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticate...
CVE-2023-31100HIGH7.1Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now