2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-42919MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma ...
CVE-2023-42914MEDIUM6.3The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17....
CVE-2023-42900MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2. An app may be able to access use...
CVE-2023-42898MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 ...
CVE-2023-42897MEDIUM4.6The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical...
CVE-2023-42894MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, mac...
CVE-2023-42891MEDIUM5.5An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ve...
CVE-2023-42884MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS...
CVE-2023-42883MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 a...
CVE-2023-42479MEDIUM6.1An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, ...
CVE-2023-42476MEDIUM6.8SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into We...
CVE-2023-36654MEDIUM6.5Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated at...
CVE-2023-36652MEDIUM4.3A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated att...
CVE-2023-49802MEDIUM6.1The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-d...
CVE-2023-45292MEDIUM5.3When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the fi...
CVE-2023-49796MEDIUM5.3MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file wr...
CVE-2023-49494MEDIUM6.1DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component selec...
CVE-2023-49490MEDIUM6.1XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admi...
CVE-2023-49488MEDIUM6.1A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or...
CVE-2023-5955MEDIUM4.8The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could all...
CVE-2023-5940MEDIUM4.8The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which coul...
CVE-2023-5907MEDIUM6.5The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrat...
CVE-2023-5757MEDIUM4.8The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-5750MEDIUM6.1The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-5749MEDIUM6.1The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the pa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now