2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-49734MEDIUM6.5An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be...
CVE-2023-49489MEDIUM6.1Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive in...
CVE-2023-49006MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive...
CVE-2023-46104MEDIUM6.5Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data...
CVE-2023-50376MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider S...
CVE-2023-5432MEDIUM5.4The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortc...
CVE-2023-5413MEDIUM5.4The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-...
CVE-2023-42015MEDIUM4.3IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML inje...
CVE-2023-6488MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2023-6918MEDIUM5.3A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different sup...
CVE-2023-6927MEDIUM6.1A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using...
CVE-2023-47558MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mahlamusa Who Hit ...
CVE-2023-6355MEDIUM6.8 Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechani...
CVE-2023-41967MEDIUM4.6 Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacke...
CVE-2023-23584MEDIUM4.3 An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to ...
CVE-2023-23576MEDIUM4.3 Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site ...
CVE-2023-22439MEDIUM4.3 Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in...
CVE-2023-40691MEDIUM4.9IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2023-6289MEDIUM4.3The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings,...
CVE-2023-6077MEDIUM6.5The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and ca...
CVE-2023-6065MEDIUM5.3The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which all...
CVE-2023-5348MEDIUM6.1The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or e...
CVE-2023-5005MEDIUM4.8The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-p...
CVE-2023-47741MEDIUM5.3 IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser m...
CVE-2023-51385MEDIUM6.5In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now