2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-54339CRITICAL9.8Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS comman...
CVE-2023-54338HIGH8.5Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit...
CVE-2023-54337CRITICAL9.1Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows atta...
CVE-2023-54336HIGH8.5Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to...
CVE-2023-54335CRITICAL9.8eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by ma...
CVE-2023-54334CRITICAL9.8Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allow...
CVE-2023-54333HIGH8.8Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac...
CVE-2023-54332MEDIUM6.1Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject ma...
CVE-2023-54331HIGH8.5Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra...
CVE-2023-54330CRITICAL9.8Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthent...
CVE-2023-54329CRITICAL9.8Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to...
CVE-2023-54328MEDIUM6.5AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes appl...
CVE-2023-53985MEDIUM6.1Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attacker...
CVE-2023-53984HIGH8.5Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca...
CVE-2023-36331HIGH8.2Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' ...
CVE-2023-7333MEDIUM5.3A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t...
CVE-2023-5069Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52212MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issu...
CVE-2023-51513MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM F...
CVE-2023-50897CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Fil...
CVE-2023-49186HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma...
CVE-2023-7332HIGH7.1PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handl...
CVE-2023-7331MEDIUM5.1A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerabi...
CVE-2023-54327CRITICAL9.8Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers t...
CVE-2023-54163HIGH8.8NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attac...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now