2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-31002MEDIUM5.5IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that c...
CVE-2023-39196MEDIUM5.3Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern...
CVE-2023-40355MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0...
CVE-2023-6388MEDIUM5Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because ...
CVE-2023-45227MEDIUM5.4 An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr...
CVE-2023-45222MEDIUM5.4 An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript ...
CVE-2023-45213MEDIUM6.5 A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a...
CVE-2023-42765MEDIUM5.4 An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si...
CVE-2023-40544MEDIUM5.7 An attacker with access to the network where the affected devices are located could maliciously actions to ob...
CVE-2023-40143MEDIUM5.4 An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary...
CVE-2023-46183MEDIUM4.4IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could all...
CVE-2023-32474MEDIUM6.6 Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount p...
CVE-2023-28063MEDIUM4.4 Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin...
CVE-2023-52239MEDIUM6.5The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.
CVE-2023-33064MEDIUM5.5Transient DOS in Audio when invoking callback function of ASM driver.
CVE-2023-33060MEDIUM5.5Transient DOS in Core when DDR memory check is called while DDR is not initialized.
CVE-2023-47022MEDIUM6.5Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for ...
CVE-2023-7029MEDIUM5.4The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2023-6983MEDIUM4.3The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure ...
CVE-2023-6982MEDIUM5.4The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cr...
CVE-2023-6963MEDIUM5.3The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0...
CVE-2023-6959MEDIUM4.3The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2023-6953MEDIUM5.4The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2023-6884MEDIUM5.4This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to,...
CVE-2023-6808MEDIUM5.4The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Script...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now