2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40758CRITICAL9.8User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a diffe...
CVE-2023-40757CRITICAL9.8User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a d...
CVE-2023-40756CRITICAL9.8User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a differ...
CVE-2023-40755MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widge...
CVE-2023-40754HIGH8.8In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile...
CVE-2023-40753MEDIUM5.4There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support S...
CVE-2023-40752MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer W...
CVE-2023-40751MEDIUM6.1PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.
CVE-2023-40750MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing S...
CVE-2023-40749CRITICAL9.8PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
CVE-2023-40748CRITICAL9.8PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
CVE-2023-36481HIGH7.5An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100...
CVE-2023-34758HIGH8.1Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-t...
CVE-2023-26095HIGH7.5ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a cr...
CVE-2023-40195HIGH8.8Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Soft...
CVE-2023-27604HIGH8.8Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parame...
CVE-2023-38030HIGH7.5 Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. A...
CVE-2023-38029CRITICAL9.8 Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within t...
CVE-2023-38028CRITICAL9.1 Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can...
CVE-2023-38027CRITICAL9.8SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthen...
CVE-2023-38026CRITICAL9.8 SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can explo...
CVE-2023-38025CRITICAL9.8 SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthe...
CVE-2023-38024CRITICAL9.8 SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An...
CVE-2023-4561MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.
CVE-2023-4560MEDIUM6.5Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now