2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34656HIGH8.8An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru...
CVE-2023-34599MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to ex...
CVE-2023-34598CRITICAL9.8Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files...
CVE-2023-33466HIGH8.8Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file...
CVE-2023-3458CRITICAL9.8A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vul...
CVE-2023-3457CRITICAL9.8A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk...
CVE-2023-34735CRITICAL9.8Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
CVE-2023-34487CRITICAL9.8itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points e...
CVE-2023-34486MEDIUM6.1itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote co...
CVE-2023-36617MEDIUM5.3A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that ha...
CVE-2023-22886HIGH8.8Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provide...
CVE-2023-3447HIGH7.6The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up ...
CVE-2023-34834MEDIUM5.3A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attacker...
CVE-2023-34831MEDIUM5.4The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security is...
CVE-2023-34734MEDIUM4.8Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) .
CVE-2023-34648MEDIUM6.1A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v....
CVE-2023-37237HIGH7.2In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell...
CVE-2023-2982CRITICAL9.8The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe...
CVE-2023-1602MEDIUM4.8The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insuf...
CVE-2023-36476MEDIUM5.5calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of cala...
CVE-2023-32610HIGH7.5Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) conditi...
CVE-2023-34843HIGH7.5Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
CVE-2023-34738CRITICAL9.8Chemex through 3.7.1 is vulnerable to arbitrary file upload.
CVE-2023-33661MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRo...
CVE-2023-36475CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now