2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6807MEDIUM5.4The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta...
CVE-2023-6701MEDIUM5.4The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text fie...
CVE-2023-6557MEDIUM5.3The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2023-6526MEDIUM5.4The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via c...
CVE-2023-4637MEDIUM5.3The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r...
CVE-2023-34042MEDIUM5.5The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extra...
CVE-2023-22819MEDIUM4.9An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co...
CVE-2023-22817MEDIUM5.5Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL ...
CVE-2023-6028MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Auto...
CVE-2023-7216MEDIUM5.3A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t...
CVE-2023-51504MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's ...
CVE-2023-52426MEDIUM5.5libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
CVE-2023-6240MEDIUM6.5A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue ma...
CVE-2023-50947MEDIUM5.4IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2023-33851MEDIUM4.9IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could rev...
CVE-2023-49950MEDIUM5.4The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being display...
CVE-2023-37528MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att...
CVE-2023-32329MEDIUM5.5IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V...
CVE-2023-37527MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly al...
CVE-2023-50359MEDIUM6.7An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited...
CVE-2023-47561MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co...
CVE-2023-45028MEDIUM4.9An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. I...
CVE-2023-45027MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2023-45026MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2023-41274MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now