2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-48825MEDIUM5.4Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Cod...
CVE-2023-48824MEDIUM5.4BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or key...
CVE-2023-48208MEDIUM6.1A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via th...
CVE-2023-48206MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to injec...
CVE-2023-48205MEDIUM5.3Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emai...
CVE-2023-43299MEDIUM5.3An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of...
CVE-2023-43298MEDIUM5.3An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak...
CVE-2023-48172MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript...
CVE-2023-46916MEDIUM4.3Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to...
CVE-2023-46857MEDIUM5.4Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomp...
CVE-2023-43103MEDIUM6.1An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. ...
CVE-2023-43102MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox...
CVE-2023-6568MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the han...
CVE-2023-28017MEDIUM5.4HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi...
CVE-2023-40238MEDIUM5.5A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.4...
CVE-2023-5714MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-5713MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-5712MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-5711MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-5710MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-46218MEDIUM6.5This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than w...
CVE-2023-6566MEDIUM6.5Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-6393MEDIUM5.3A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the ...
CVE-2023-39326MEDIUM5.3A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read man...
CVE-2023-6459MEDIUM5.3Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now