2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7124MEDIUM6.1A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unk...
CVE-2023-34829MEDIUM6.5Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
CVE-2023-49003MEDIUM5.3An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interac...
CVE-2023-46918MEDIUM4.6Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an...
CVE-2023-51079MEDIUM5.3A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java c...
CVE-2023-51074MEDIUM5.3json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
CVE-2023-46919MEDIUM6.3Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) ...
CVE-2023-51443MEDIUM5.9FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-4641MEDIUM5.5A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password ...
CVE-2023-49438MEDIUM6.1An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspectin...
CVE-2023-48003MEDIUM6.1An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redire...
CVE-2023-6268MEDIUM6.1The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting...
CVE-2023-6166MEDIUM6.1The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, lead...
CVE-2023-6155MEDIUM5.3The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX acti...
CVE-2023-5980MEDIUM4.8The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow...
CVE-2023-5672MEDIUM6.5The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to em...
CVE-2023-51363MEDIUM6.5VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's ...
CVE-2023-50339MEDIUM5.4Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v...
CVE-2023-50332MEDIUM6.5Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6...
CVE-2023-50294MEDIUM6.5The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As ...
CVE-2023-50175MEDIUM5.4Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/ma...
CVE-2023-49807MEDIUM5.4Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this ...
CVE-2023-49779MEDIUM5.4Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerabil...
CVE-2023-49598MEDIUM5.4Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0...
CVE-2023-49119MEDIUM5.4Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerabili...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now