2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38941CRITICAL9.8django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspa...
CVE-2023-36159MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers...
CVE-2023-36158MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run...
CVE-2023-36141MEDIUM5.3User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, w...
CVE-2023-36139CRITICAL9.8In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on th...
CVE-2023-36138MEDIUM6.1PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview...
CVE-2023-36137MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduli...
CVE-2023-36135HIGH7.5User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, whe...
CVE-2023-36134CRITICAL9.8In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the ...
CVE-2023-36133CRITICAL9.8PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
CVE-2023-36132CRITICAL9.8PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
CVE-2023-36131CRITICAL9.8PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation ...
CVE-2023-33665CRITICAL9.8ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.ph...
CVE-2023-30297HIGH7An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code v...
CVE-2023-0525HIGH7.5Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000...
CVE-2023-38952HIGH7.5Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due ...
CVE-2023-38951CRITICAL9.8ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arb...
CVE-2023-38950HIGH7.5A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit...
CVE-2023-38949HIGH7.5An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrato...
CVE-2023-37501MEDIUM6.1A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user...
CVE-2023-37500MEDIUM6.1A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacke...
CVE-2023-37499MEDIUM6.1A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An a...
CVE-2023-37498HIGH8.8A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It...
CVE-2023-37497HIGH8.8The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated ...
CVE-2023-30958MEDIUM6.1A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now