2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31614HIGH7.5An issue in the mp_box_deserialize_string function in openlink virtuoso-opensource v7.2.9 allows attackers to cause a De...
CVE-2023-31613HIGH7.5An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denia...
CVE-2023-31612HIGH7.5An issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Ser...
CVE-2023-31611HIGH7.5An issue in the __libc_longjmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Se...
CVE-2023-31610HIGH7.5An issue in the _IO_default_xsputn component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial o...
CVE-2023-31609HIGH7.5An issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of...
CVE-2023-31608HIGH7.5An issue in the artm_div_int component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Serv...
CVE-2023-31607HIGH7.5An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Ser...
CVE-2023-29861CRITICAL9.8An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted requ...
CVE-2023-31845HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
CVE-2023-31844HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.
CVE-2023-31843HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.
CVE-2023-31842HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.
CVE-2023-2180HIGH7.5The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be d...
CVE-2023-2179MEDIUM6.5The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when up...
CVE-2023-2009MEDIUM4.8Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could...
CVE-2023-29862CRITICAL9.8An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the ...
CVE-2023-23682MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0...
CVE-2023-1915MEDIUM6.1The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputt...
CVE-2023-1890MEDIUM6.1The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes...
CVE-2023-1839MEDIUM4.8The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its sett...
CVE-2023-1835MEDIUM6.1The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it bac...
CVE-2023-1596MEDIUM6.1The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in th...
CVE-2023-1549HIGH7.2The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high...
CVE-2023-1207HIGH7.2This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now