2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27435HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions.
CVE-2023-0506HIGH8.8The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation...
CVE-2023-5353MEDIUM6.5Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-42508MEDIUM6.5JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi...
CVE-2023-40212MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versio...
CVE-2023-40202HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions.
CVE-2023-40201HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation ...
CVE-2023-40199HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.
CVE-2023-40198MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions.
CVE-2023-40009MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.
CVE-2023-39159MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions...
CVE-2023-32792MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker...
CVE-2023-32791MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker...
CVE-2023-32790MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inj...
CVE-2023-32671MEDIUM5.4A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an at...
CVE-2023-32670MEDIUM5.4Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privile...
CVE-2023-32669MEDIUM5.4Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated us...
CVE-2023-2681HIGH8.8An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote...
CVE-2023-5351MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-5350CRITICAL9.1 SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-4103HIGH8.8QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not c...
CVE-2023-4102HIGH8.8QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficien...
CVE-2023-4101MEDIUM6.5The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has suffi...
CVE-2023-4100HIGH8.2Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS c...
CVE-2023-4099MEDIUM6.5The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now