2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39023CRITICAL9.8university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compas...
CVE-2023-39022CRITICAL9.8oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util....
CVE-2023-39021CRITICAL9.8wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.my...
CVE-2023-39020CRITICAL9.8stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford....
CVE-2023-39018CRITICAL9.8FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg...
CVE-2023-39017CRITICAL9.8quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee...
CVE-2023-39016CRITICAL9.8bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.framewor...
CVE-2023-39015CRITICAL9.8webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecr...
CVE-2023-39013CRITICAL9.8Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.serv...
CVE-2023-39010CRITICAL9.8BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.Calibration...
CVE-2023-38992CRITICAL9.8jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeD...
CVE-2023-37754CRITICAL9.8PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at...
CVE-2023-37467MEDIUM5.4Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches,...
CVE-2023-39190Rejected reason: CVE-2023-39190 was found to be a duplicate of CVE-2023-31436. Please see https://access.redhat.com/secu...
CVE-2023-31937HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31936HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31935MEDIUM4.8Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensiti...
CVE-2023-31934MEDIUM4.8Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensiti...
CVE-2023-31933HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31932HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-2685MEDIUM6.3A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry ...
CVE-2023-3670HIGH7.3In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions ...
CVE-2023-3990MEDIUM6.1A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of t...
CVE-2023-3989MEDIUM6.1A vulnerability was found in SourceCodester Jewelry Store System 1.0. It has been rated as problematic. Affected by this...
CVE-2023-3988CRITICAL9.8A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now