2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-54339 | CRITICAL | 9.8 | 1.5% | Jan 13, 2026 | Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS comman... |
| CVE-2023-54338 | HIGH | 8.5 | 0.1% | Jan 13, 2026 | Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit... |
| CVE-2023-54337 | CRITICAL | 9.1 | 0.5% | Jan 13, 2026 | Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows atta... |
| CVE-2023-54336 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to... |
| CVE-2023-54335 | CRITICAL | 9.8 | 5.0% | Jan 13, 2026 | eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by ma... |
| CVE-2023-54334 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allow... |
| CVE-2023-54333 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac... |
| CVE-2023-54332 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject ma... |
| CVE-2023-54331 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra... |
| CVE-2023-54330 | CRITICAL | 9.8 | 0.7% | Jan 13, 2026 | Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthent... |
| CVE-2023-54329 | CRITICAL | 9.8 | 1.0% | Jan 13, 2026 | Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to... |
| CVE-2023-54328 | MEDIUM | 6.5 | 0.4% | Jan 13, 2026 | AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes appl... |
| CVE-2023-53985 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attacker... |
| CVE-2023-53984 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca... |
| CVE-2023-36331 | HIGH | 8.2 | 0.2% | Jan 12, 2026 | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' ... |
| CVE-2023-7333 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t... |
| CVE-2023-5069 | — | — | — | Jan 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-52212 | MEDIUM | 5.4 | 0.1% | Jan 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issu... |
| CVE-2023-51513 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM F... |
| CVE-2023-50897 | CRITICAL | 9.1 | 0.3% | Jan 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Fil... |
| CVE-2023-49186 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma... |
| CVE-2023-7332 | HIGH | 7.1 | 0.4% | Dec 31, 2025 | PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handl... |
| CVE-2023-7331 | MEDIUM | 5.1 | 0.2% | Dec 31, 2025 | A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerabi... |
| CVE-2023-54327 | CRITICAL | 9.8 | 0.6% | Dec 30, 2025 | Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers t... |
| CVE-2023-54163 | HIGH | 8.8 | 0.3% | Dec 30, 2025 | NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attac... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now