2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37508MEDIUM6.1HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v...
CVE-2023-20572MEDIUM5.6An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th...
CVE-2023-33854MEDIUM5.3IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a...
CVE-2023-32959MEDIUM4.3Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access ...
CVE-2023-25969MEDIUM5.4Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectl...
CVE-2023-40200MEDIUM5.3Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an...
CVE-2023-43686MEDIUM6.2An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox prefere...
CVE-2023-52951MEDIUM5.9A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ...
CVE-2023-7346MEDIUM4.1Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i...
CVE-2023-7345MEDIUM6.9Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th...
CVE-2023-31309MEDIUM6.8Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload...
CVE-2023-30059MEDIUM5.4An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use...
CVE-2023-47268MEDIUM5.3In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar...
CVE-2023-42345MEDIUM6.1A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
CVE-2023-42343MEDIUM6.1A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
CVE-2023-54349MEDIUM6.1AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject...
CVE-2023-20585MEDIUM5.6Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hy...
CVE-2023-5872MEDIUM4.3In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames th...
CVE-2023-54364MEDIUM6.1Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to i...
CVE-2023-54363MEDIUM6.1Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to ...
CVE-2023-54362MEDIUM6.1Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to ...
CVE-2023-54361MEDIUM6.1Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inje...
CVE-2023-54360MEDIUM6.1Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicio...
CVE-2023-54358MEDIUM6.1WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated ...
CVE-2023-7340MEDIUM4.3Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now