2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29630 | CRITICAL | 9.8 | 1.0% | Jun 5, 2023 | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. |
| CVE-2023-29629 | CRITICAL | 9.8 | 1.0% | Jun 5, 2023 | PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php. |
| CVE-2023-33970 | MEDIUM | 6.5 | 0.5% | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a... |
| CVE-2023-33969 | MEDIUM | 5.4 | 0.5% | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scriptin... |
| CVE-2023-33968 | MEDIUM | 5.4 | 0.4% | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are... |
| CVE-2023-33956 | MEDIUM | 6.5 | 0.6% | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are... |
| CVE-2023-29344 | HIGH | 7.8 | 0.9% | Jun 5, 2023 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2023-33524 | MEDIUM | 5.3 | 1.0% | Jun 5, 2023 | Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumer... |
| CVE-2023-3109 | MEDIUM | 5.4 | 0.5% | Jun 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository admidio/admidio prior to 4.2.8. |
| CVE-2023-33733 | HIGH | 7.8 | 2.3% | Jun 5, 2023 | Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. |
| CVE-2023-33693 | MEDIUM | 5.5 | 0.4% | Jun 5, 2023 | A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) ... |
| CVE-2023-33690 | MEDIUM | 6.5 | 0.9% | Jun 5, 2023 | SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special charac... |
| CVE-2023-33518 | MEDIUM | 5.3 | 0.5% | Jun 5, 2023 | emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain... |
| CVE-2023-33386 | CRITICAL | 9.8 | 1.0% | Jun 5, 2023 | MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background. |
| CVE-2023-32766 | MEDIUM | 6.1 | 0.6% | Jun 5, 2023 | Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three ... |
| CVE-2023-2634 | MEDIUM | 4.8 | 0.5% | Jun 5, 2023 | The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2023-2572 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes... |
| CVE-2023-2571 | MEDIUM | 6.1 | 2.1% | Jun 5, 2023 | The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes... |
| CVE-2023-2503 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting i... |
| CVE-2023-2489 | MEDIUM | 4.8 | 0.4% | Jun 5, 2023 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape... |
| CVE-2023-2488 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape... |
| CVE-2023-2472 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise... |
| CVE-2023-2337 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, lead... |
| CVE-2023-2224 | MEDIUM | 4.8 | 0.9% | Jun 5, 2023 | The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-0900 | HIGH | 7.2 | 3.2% | Jun 5, 2023 | The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now