2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5873 | MEDIUM | 5.4 | 0.3% | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0. |
| CVE-2023-5464 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version... |
| CVE-2023-5439 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u... |
| CVE-2023-5438 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5437 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t... |
| CVE-2023-5436 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a... |
| CVE-2023-5435 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in ve... |
| CVE-2023-5434 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ... |
| CVE-2023-5433 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and... |
| CVE-2023-5431 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in... |
| CVE-2023-5430 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5429 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a... |
| CVE-2023-5428 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode ... |
| CVE-2023-5412 | MEDIUM | 6.5 | 1.5% | Oct 31, 2023 | The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcod... |
| CVE-2023-46210 | MEDIUM | 4.8 | 0.3% | Oct 31, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions. |
| CVE-2023-46451 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field. |
| CVE-2023-46361 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. |
| CVE-2023-45996 | HIGH | 8.8 | 1.1% | Oct 31, 2023 | SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker ... |
| CVE-2023-43139 | CRITICAL | 9.8 | 0.9% | Oct 31, 2023 | An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and c... |
| CVE-2023-36263 | CRITICAL | 9.8 | 0.5% | Oct 31, 2023 | Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontCo... |
| CVE-2023-47174 | CRITICAL | 9.8 | 1.0% | Oct 31, 2023 | Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is... |
| CVE-2023-46356 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection.... |
| CVE-2023-45378 | CRITICAL | 9.8 | 0.5% | Oct 31, 2023 | In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL inj... |
| CVE-2023-27846 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges... |
| CVE-2023-46040 | MEDIUM | 5.4 | 0.5% | Oct 31, 2023 | Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now