2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-50136MEDIUM5.4Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field wh...
CVE-2023-38827MEDIUM6.1Cross Site Scripting vulnerability in Follet School Solutions Destiny v.20_0_1_AU4 and later allows a remote attacker to...
CVE-2023-6129MEDIUM6.5Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the inter...
CVE-2023-7223MEDIUM6.5A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown ...
CVE-2023-51744MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < ...
CVE-2023-49722MEDIUM6.5Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the devic...
CVE-2023-6149MEDIUM6.5 Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, w...
CVE-2023-6148MEDIUM5.4Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu...
CVE-2023-50974MEDIUM5.5In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appw...
CVE-2023-6147MEDIUM6.5Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu...
CVE-2023-6842MEDIUM4.8The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress i...
CVE-2023-6830MEDIUM6.1The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu...
CVE-2023-50932MEDIUM5.4An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, th...
CVE-2023-50931MEDIUM5.4An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the...
CVE-2023-6788MEDIUM5.4The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2023-6594MEDIUM4.8The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti...
CVE-2023-36629MEDIUM5.5The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
CVE-2023-27000MEDIUM6.1Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod...
CVE-2023-26998MEDIUM5.4Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod...
CVE-2023-46906MEDIUM4.9juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status cod...
CVE-2023-52198MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd P...
CVE-2023-52197MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads In...
CVE-2023-52196MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Boo...
CVE-2023-27739MEDIUM6.1easyXDM 2.5 allows XSS via the xdm_e parameter.
CVE-2023-52271MEDIUM6.5The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now