2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29630CRITICAL9.8PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.
CVE-2023-29629CRITICAL9.8PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.
CVE-2023-33970MEDIUM6.5Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a...
CVE-2023-33969MEDIUM5.4Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scriptin...
CVE-2023-33968MEDIUM5.4Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are...
CVE-2023-33956MEDIUM6.5Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are...
CVE-2023-29344HIGH7.8Microsoft Office Remote Code Execution Vulnerability
CVE-2023-33524MEDIUM5.3Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumer...
CVE-2023-3109MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository admidio/admidio prior to 4.2.8.
CVE-2023-33733HIGH7.8Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
CVE-2023-33693MEDIUM5.5A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) ...
CVE-2023-33690MEDIUM6.5SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special charac...
CVE-2023-33518MEDIUM5.3emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain...
CVE-2023-33386CRITICAL9.8MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
CVE-2023-32766MEDIUM6.1Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three ...
CVE-2023-2634MEDIUM4.8The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-2572MEDIUM6.1The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes...
CVE-2023-2571MEDIUM6.1The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes...
CVE-2023-2503MEDIUM6.1The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting i...
CVE-2023-2489MEDIUM4.8The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape...
CVE-2023-2488MEDIUM6.1The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape...
CVE-2023-2472MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise...
CVE-2023-2337MEDIUM6.1The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, lead...
CVE-2023-2224MEDIUM4.8The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-0900HIGH7.2The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now