2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30177MEDIUM6.1CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
CVE-2023-29200MEDIUM6.5Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can li...
CVE-2023-23838MEDIUM6.5Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the serv...
CVE-2023-23837HIGH7.5No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2023-28847HIGH7.5Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24....
CVE-2023-25484MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 v...
CVE-2023-30402MEDIUM5.5YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: Th...
CVE-2023-29552HIGH7.5The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services....
CVE-2023-25314MEDIUM6.1Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain se...
CVE-2023-25313CRITICAL9.8OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbit...
CVE-2023-27105CRITICAL9.8A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and...
CVE-2023-2281MEDIUM4.3When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi...
CVE-2023-29779HIGH7.5Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send ma...
CVE-2023-30417MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scr...
CVE-2023-26843MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr...
CVE-2023-26841MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password exc...
CVE-2023-26840MEDIUM5.3A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set...
CVE-2023-26839MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing ...
CVE-2023-26058MEDIUM6.5An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input va...
CVE-2023-26057MEDIUM6.5An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. In...
CVE-2023-25348HIGH7.8ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields wh...
CVE-2023-25347MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web sc...
CVE-2023-25346MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web ...
CVE-2023-27619MEDIUM5.4Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 version...
CVE-2023-26098HIGH7.8An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now