2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-48406MEDIUM6.7there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. Thi...
CVE-2023-48405MEDIUM6.7there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to ...
CVE-2023-48401MEDIUM5.5In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check....
CVE-2023-48399MEDIUM5.5In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a miss...
CVE-2023-48397MEDIUM4.9In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lea...
CVE-2023-23372MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2023-6609MEDIUM6.1A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi...
CVE-2023-6146MEDIUM5.4 A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in th...
CVE-2023-49487MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management depar...
CVE-2023-49486MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department...
CVE-2023-49485MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management departmen...
CVE-2023-49484MEDIUM5.4Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management depart...
CVE-2023-49444MEDIUM5.4An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a craft...
CVE-2023-45866MEDIUM6.3Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encry...
CVE-2023-48928MEDIUM6.1Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' par...
CVE-2023-6599MEDIUM4.3Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-46693MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title param...
CVE-2023-6578MEDIUM6.5A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown ...
CVE-2023-6577MEDIUM4.3A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affe...
CVE-2023-38174MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-36880MEDIUM4.8Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-6333MEDIUM5.4 The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could all...
CVE-2023-48958MEDIUM5.5gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.
CVE-2023-47440MEDIUM6.5Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be inc...
CVE-2023-46871MEDIUM5.3GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:30...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now