2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39968MEDIUM6.1jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links...
CVE-2023-39652CRITICAL9.8theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVi...
CVE-2023-38969MEDIUM5.4Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted pa...
CVE-2023-41109CRITICAL9.8SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
CVE-2023-39578MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute...
CVE-2023-39348MEDIUM5.3Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is imprope...
CVE-2023-35785HIGH8.1Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and bel...
CVE-2023-39810HIGH7.8An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
CVE-2023-39709MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-39562MEDIUM5.5GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at b...
CVE-2023-40590HIGH7.8 GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for...
CVE-2023-39062MEDIUM6.1Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code v...
CVE-2023-39560CRITICAL9.8ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\inse...
CVE-2023-1997HIGH8.8An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3...
CVE-2023-40846CRITICAL9.8Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.
CVE-2023-39708MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attack...
CVE-2023-40767CRITICAL9.8User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where ...
CVE-2023-40766CRITICAL9.8User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where...
CVE-2023-40765CRITICAL9.8User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a...
CVE-2023-40764CRITICAL9.8User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a dif...
CVE-2023-40763CRITICAL9.8User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a di...
CVE-2023-40762CRITICAL9.8User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a dif...
CVE-2023-40761CRITICAL9.8User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a d...
CVE-2023-40760CRITICAL9.8User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a ...
CVE-2023-40759CRITICAL9.8User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, whe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now