2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5873MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
CVE-2023-5464MEDIUM6.5The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version...
CVE-2023-5439MEDIUM6.5The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u...
CVE-2023-5438MEDIUM6.5The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-5437MEDIUM6.5The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t...
CVE-2023-5436MEDIUM6.5The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5435MEDIUM6.5The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in ve...
CVE-2023-5434MEDIUM6.5The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ...
CVE-2023-5433MEDIUM6.5The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and...
CVE-2023-5431MEDIUM6.5The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in...
CVE-2023-5430MEDIUM6.5The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-5429MEDIUM6.5The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5428MEDIUM6.5The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode ...
CVE-2023-5412MEDIUM6.5The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcod...
CVE-2023-46210MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions.
CVE-2023-46451MEDIUM5.4Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
CVE-2023-46361MEDIUM6.5Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.
CVE-2023-45996HIGH8.8SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker ...
CVE-2023-43139CRITICAL9.8An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and c...
CVE-2023-36263CRITICAL9.8Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontCo...
CVE-2023-47174CRITICAL9.8Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is...
CVE-2023-46356CRITICAL9.8In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection....
CVE-2023-45378CRITICAL9.8In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL inj...
CVE-2023-27846CRITICAL9.8SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges...
CVE-2023-46040MEDIUM5.4Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now