2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38765 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the member... |
| CVE-2023-38764 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the birthm... |
| CVE-2023-38763 | MEDIUM | 6.5 | 0.7% | Aug 8, 2023 | SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the FundRa... |
| CVE-2023-38762 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friend... |
| CVE-2023-38761 | MEDIUM | 6.1 | 0.7% | Aug 8, 2023 | Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a c... |
| CVE-2023-38760 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the role a... |
| CVE-2023-38759 | HIGH | 8.8 | 0.3% | Aug 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to... |
| CVE-2023-38758 | MEDIUM | 5.4 | 0.5% | Aug 8, 2023 | Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privi... |
| CVE-2023-3653 | MEDIUM | 5.4 | 0.4% | Aug 8, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Comm... |
| CVE-2023-3652 | MEDIUM | 6.1 | 0.4% | Aug 8, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Comm... |
| CVE-2023-3651 | CRITICAL | 9.8 | 0.6% | Aug 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Comm... |
| CVE-2023-36306 | MEDIUM | 6.1 | 3.8% | Aug 8, 2023 | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to exec... |
| CVE-2023-36136 | MEDIUM | 6.5 | 0.2% | Aug 8, 2023 | PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) a... |
| CVE-2023-33756 | HIGH | 7.5 | 0.9% | Aug 8, 2023 | An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversa... |
| CVE-2023-2423 | HIGH | 7.5 | 0.6% | Aug 8, 2023 | A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications ... |
| CVE-2023-24698 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perf... |
| CVE-2023-4219 | HIGH | 7.5 | 0.7% | Aug 8, 2023 | A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected b... |
| CVE-2023-38384 | MEDIUM | 6.1 | 0.3% | Aug 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions. |
| CVE-2023-36546 | — | — | — | Aug 8, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-32292 | MEDIUM | 4.8 | 0.3% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GetButton Chat Button by GetButton.Io plugin <= 1.8.9.... |
| CVE-2023-31221 | MEDIUM | 4.8 | 0.3% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ransom Christofferson PDQ CSV plugin <= 1.0.0 versions... |
| CVE-2023-30482 | MEDIUM | 5.4 | 0.3% | Aug 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in VillaTheme WPBulky plugin <= 1.0.10 versions. |
| CVE-2023-28934 | MEDIUM | 4.8 | 0.3% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versi... |
| CVE-2023-28931 | MEDIUM | 4.8 | 0.3% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. |
| CVE-2023-28773 | MEDIUM | 5.4 | 0.3% | Aug 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kolja Nolte Secondary Title plugin <= 2.0.9.1 ve... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now