2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40956HIGH8.8A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute ...
CVE-2023-40955HIGH8.8A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix...
CVE-2023-39642CRITICAL9.8Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCat...
CVE-2023-39641CRITICAL9.8Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component Psaffi...
CVE-2023-39639CRITICAL9.8LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::get...
CVE-2023-42405CRITICAL9.8SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` para...
CVE-2023-41592MEDIUM5.4Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-38891HIGH8.8SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the ...
CVE-2023-40869MEDIUM6.1Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute a...
CVE-2023-40868HIGH8.8Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbi...
CVE-2023-39638CRITICAL9.8D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc...
CVE-2023-42362MEDIUM5.4An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands ...
CVE-2023-41160MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ...
CVE-2023-41159MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote a...
CVE-2023-41156MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote atta...
CVE-2023-38912CRITICAL9.8SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code vi...
CVE-2023-37756CRITICAL9.8I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creatio...
CVE-2023-25588MEDIUM5.5A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s...
CVE-2023-25586MEDIUM5.5A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an ...
CVE-2023-25585MEDIUM5.5A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra...
CVE-2023-25584HIGH7.1An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
CVE-2023-4972CRITICAL9.8Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This is...
CVE-2023-4965MEDIUM4.8A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2023-4702CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa...
CVE-2023-4676MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro al...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now