2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40956 | HIGH | 8.8 | 1.0% | Sep 15, 2023 | A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute ... |
| CVE-2023-40955 | HIGH | 8.8 | 1.1% | Sep 15, 2023 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix... |
| CVE-2023-39642 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCat... |
| CVE-2023-39641 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component Psaffi... |
| CVE-2023-39639 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::get... |
| CVE-2023-42405 | CRITICAL | 9.8 | 1.0% | Sep 14, 2023 | SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` para... |
| CVE-2023-41592 | MEDIUM | 5.4 | 0.9% | Sep 14, 2023 | Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2023-38891 | HIGH | 8.8 | 0.9% | Sep 14, 2023 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the ... |
| CVE-2023-40869 | MEDIUM | 6.1 | 1.0% | Sep 14, 2023 | Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute a... |
| CVE-2023-40868 | HIGH | 8.8 | 1.2% | Sep 14, 2023 | Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbi... |
| CVE-2023-39638 | CRITICAL | 9.8 | 3.0% | Sep 14, 2023 | D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc... |
| CVE-2023-42362 | MEDIUM | 5.4 | 0.6% | Sep 14, 2023 | An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands ... |
| CVE-2023-41160 | MEDIUM | 5.4 | 0.5% | Sep 14, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ... |
| CVE-2023-41159 | MEDIUM | 5.4 | 0.4% | Sep 14, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote a... |
| CVE-2023-41156 | MEDIUM | 5.4 | 0.4% | Sep 14, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote atta... |
| CVE-2023-38912 | CRITICAL | 9.8 | 1.4% | Sep 14, 2023 | SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-37756 | CRITICAL | 9.8 | 1.2% | Sep 14, 2023 | I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creatio... |
| CVE-2023-25588 | MEDIUM | 5.5 | 0.4% | Sep 14, 2023 | A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s... |
| CVE-2023-25586 | MEDIUM | 5.5 | 0.3% | Sep 14, 2023 | A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an ... |
| CVE-2023-25585 | MEDIUM | 5.5 | 0.4% | Sep 14, 2023 | A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra... |
| CVE-2023-25584 | HIGH | 7.1 | 0.4% | Sep 14, 2023 | An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. |
| CVE-2023-4972 | CRITICAL | 9.8 | 0.6% | Sep 14, 2023 | Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This is... |
| CVE-2023-4965 | MEDIUM | 4.8 | 0.5% | Sep 14, 2023 | A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown fun... |
| CVE-2023-4702 | CRITICAL | 9.8 | 0.7% | Sep 14, 2023 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa... |
| CVE-2023-4676 | MEDIUM | 6.1 | 0.3% | Sep 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro al... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now