2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7143MEDIUM4.8A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this...
CVE-2023-52085MEDIUM5.4Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker F...
CVE-2023-52084MEDIUM5.4Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include...
CVE-2023-52083MEDIUM4.8Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission...
CVE-2023-50448MEDIUM6.5In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially priv...
CVE-2023-7136MEDIUM5.4A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vuln...
CVE-2023-7135MEDIUM5.4A vulnerability classified as problematic has been found in code-projects Record Management System 1.0. Affected is an u...
CVE-2023-7133MEDIUM6.1A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unkn...
CVE-2023-7132MEDIUM5.4A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problemati...
CVE-2023-52081MEDIUM5.3ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is...
CVE-2023-52079MEDIUM6.5msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePac...
CVE-2023-50267MEDIUM4.3MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can...
CVE-2023-50470MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute...
CVE-2023-50860MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Ap...
CVE-2023-50859MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfu...
CVE-2023-50836MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML For...
CVE-2023-51501MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Cr...
CVE-2023-50874MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Word...
CVE-2023-4672MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software EC...
CVE-2023-45702MEDIUM5.5An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of ...
CVE-2023-45701MEDIUM6.5HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is retu...
CVE-2023-49469MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code...
CVE-2023-51010MEDIUM5.3An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL w...
CVE-2023-49229MEDIUM4.3An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web ser...
CVE-2023-49228MEDIUM6.4An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, wh...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now