2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-49810MEDIUM6.5A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev maste...
CVE-2023-48730MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo de...
CVE-2023-48728MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11....
CVE-2023-47861MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and...
CVE-2023-47171MEDIUM6.5An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo...
CVE-2023-6158MEDIUM6.5The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2023-5455MEDIUM6.5A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This f...
CVE-2023-48256MEDIUM6.3The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies ...
CVE-2023-48255MEDIUM6.1The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary clie...
CVE-2023-48254MEDIUM6.1The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses...
CVE-2023-48249MEDIUM6.5The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the...
CVE-2023-48248MEDIUM5.4The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary...
CVE-2023-48246MEDIUM6.5The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of t...
CVE-2023-48244MEDIUM6.1The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses...
CVE-2023-48242MEDIUM6.5The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under t...
CVE-2023-51252MEDIUM5.4PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is ...
CVE-2023-50120MEDIUM5.5MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc...
CVE-2023-49394MEDIUM6.1Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
CVE-2023-41603MEDIUM5.3D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to...
CVE-2023-41781MEDIUM6.1 There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interfac...
CVE-2023-47997MEDIUM6.5An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allo...
CVE-2023-47996MEDIUM6.5An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain informa...
CVE-2023-47995MEDIUM6.5Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0...
CVE-2023-47993MEDIUM6.5A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-o...
CVE-2023-5770MEDIUM5.4Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated att...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now