2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-48126MEDIUM5.4An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via lea...
CVE-2023-6159MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and...
CVE-2023-5612MEDIUM5.3An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16....
CVE-2023-5933MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and ...
CVE-2023-52046MEDIUM4.8Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary cod...
CVE-2023-41474MEDIUM6.5Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensiti...
CVE-2023-6282MEDIUM6.1IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerab...
CVE-2023-33760MEDIUM5.3SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow a...
CVE-2023-33758MEDIUM6.1Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via th...
CVE-2023-33757MEDIUM5.9A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Andr...
CVE-2023-6697MEDIUM6.1The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ma...
CVE-2023-51702MEDIUM6.5Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the...
CVE-2023-50944MEDIUM6.5Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code ...
CVE-2023-44001MEDIUM5.4An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ...
CVE-2023-44000MEDIUM5.4An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via l...
CVE-2023-43999MEDIUM5.4An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka...
CVE-2023-43998MEDIUM5.4An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage o...
CVE-2023-43997MEDIUM5.4An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via le...
CVE-2023-43996MEDIUM5.4An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of th...
CVE-2023-43995MEDIUM5.4An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of ...
CVE-2023-43994MEDIUM5.4An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak...
CVE-2023-43993MEDIUM5.4An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via lea...
CVE-2023-43992MEDIUM5.4An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage...
CVE-2023-43991MEDIUM5.4An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage o...
CVE-2023-43990MEDIUM5.4An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now