2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44013CRITICAL9.8Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parame...
CVE-2023-43857MEDIUM5.4Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/...
CVE-2023-43856HIGH7.5Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateContr...
CVE-2023-43830MEDIUM5.4A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to exec...
CVE-2023-43828MEDIUM5.4A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary w...
CVE-2023-43825HIGH7.8Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arb...
CVE-2023-43775MEDIUM5.3Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an une...
CVE-2023-43646HIGH7.5get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versio...
CVE-2023-43645MEDIUM5.9OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerabl...
CVE-2023-43614MEDIUM6.1Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote ...
CVE-2023-43610HIGH8.8SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with edit...
CVE-2023-43493MEDIUM4.9SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or ...
CVE-2023-43484MEDIUM6.1Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauth...
CVE-2023-43381HIGH7.5SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id...
CVE-2023-43331MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitr...
CVE-2023-43291CRITICAL9.8Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code v...
CVE-2023-43263MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the M...
CVE-2023-43234CRITICAL9.8DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_con...
CVE-2023-43232MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows at...
CVE-2023-43222CRITICAL9.8SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
CVE-2023-43216CRITICAL9.8SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
CVE-2023-43187CRITICAL9.8A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.1...
CVE-2023-43154CRITICAL9.8In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during l...
CVE-2023-42820HIGH8.2JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, pote...
CVE-2023-42819HIGH8.8JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now