2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-51492MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If So Plugin If-So...
CVE-2023-51488MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. C...
CVE-2023-51485MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hosting Pay wit...
CVE-2023-51480MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 Active ...
CVE-2023-51415MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP GiveWP – Do...
CVE-2023-51404MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My ...
CVE-2023-45698MEDIUM6.1Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropria...
CVE-2023-28077MEDIUM4.4 Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary informa...
CVE-2023-6935MEDIUM5.9wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher styl...
CVE-2023-45716MEDIUM4.1Sametime is impacted by sensitive information passed in URL.
CVE-2023-39683MEDIUM6.1Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary c...
CVE-2023-31506MEDIUM5.4A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to ...
CVE-2023-45190MEDIUM6.1IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper valida...
CVE-2023-42016MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure...
CVE-2023-32341MEDIUM6.5IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cau...
CVE-2023-51630MEDIUM6.1Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote...
CVE-2023-40264MEDIUM4.3An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path t...
CVE-2023-40262MEDIUM6.1An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stor...
CVE-2023-49101MEDIUM6.1WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against ...
CVE-2023-7169MEDIUM5.5Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof....
CVE-2023-6564MEDIUM6.5An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In project...
CVE-2023-5665MEDIUM5.4The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc...
CVE-2023-47798MEDIUM4.6Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pa...
CVE-2023-6840MEDIUM6.7An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16...
CVE-2023-6736MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now