2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34656 | HIGH | 8.8 | 0.6% | Jun 29, 2023 | An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru... |
| CVE-2023-34599 | MEDIUM | 6.1 | 1.9% | Jun 29, 2023 | Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to ex... |
| CVE-2023-34598 | CRITICAL | 9.8 | 44.9% | Jun 29, 2023 | Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files... |
| CVE-2023-33466 | HIGH | 8.8 | 3.1% | Jun 29, 2023 | Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file... |
| CVE-2023-3458 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vul... |
| CVE-2023-3457 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk... |
| CVE-2023-34735 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. |
| CVE-2023-34487 | CRITICAL | 9.8 | 0.7% | Jun 29, 2023 | itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points e... |
| CVE-2023-34486 | MEDIUM | 6.1 | 0.6% | Jun 29, 2023 | itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote co... |
| CVE-2023-36617 | MEDIUM | 5.3 | 1.5% | Jun 29, 2023 | A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that ha... |
| CVE-2023-22886 | HIGH | 8.8 | 1.1% | Jun 29, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provide... |
| CVE-2023-3447 | HIGH | 7.6 | 0.4% | Jun 29, 2023 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up ... |
| CVE-2023-34834 | MEDIUM | 5.3 | 3.3% | Jun 29, 2023 | A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attacker... |
| CVE-2023-34831 | MEDIUM | 5.4 | 0.4% | Jun 29, 2023 | The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security is... |
| CVE-2023-34734 | MEDIUM | 4.8 | 0.4% | Jun 29, 2023 | Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) . |
| CVE-2023-34648 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.... |
| CVE-2023-37237 | HIGH | 7.2 | 0.5% | Jun 29, 2023 | In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell... |
| CVE-2023-2982 | CRITICAL | 9.8 | 44.6% | Jun 29, 2023 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe... |
| CVE-2023-1602 | MEDIUM | 4.8 | 0.3% | Jun 29, 2023 | The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insuf... |
| CVE-2023-36476 | MEDIUM | 5.5 | 0.2% | Jun 29, 2023 | calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of cala... |
| CVE-2023-32610 | HIGH | 7.5 | 1.2% | Jun 29, 2023 | Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) conditi... |
| CVE-2023-34843 | HIGH | 7.5 | 6.4% | Jun 29, 2023 | Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request. |
| CVE-2023-34738 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Chemex through 3.7.1 is vulnerable to arbitrary file upload. |
| CVE-2023-33661 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRo... |
| CVE-2023-36475 | CRITICAL | 9.8 | 2.7% | Jun 28, 2023 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now