2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-47505MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elem...
CVE-2023-45050MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack...
CVE-2023-41136MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laurence/OhMyBox.I...
CVE-2023-48743MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Menard Simply...
CVE-2023-48737MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital...
CVE-2023-48336MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy S...
CVE-2023-49620MEDIUM6.5Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (whi...
CVE-2023-49081MEDIUM5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for...
CVE-2023-49077MEDIUM6.1Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability ...
CVE-2023-49076MEDIUM6.5Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSR...
CVE-2023-5275MEDIUM4.7Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv...
CVE-2023-5274MEDIUM4.7Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv...
CVE-2023-49094MEDIUM4.3Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker cou...
CVE-2023-5772MEDIUM4.3The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2023-49082MEDIUM5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo...
CVE-2023-44383MEDIUM5.4October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to...
CVE-2023-6217MEDIUM6.1 In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a refle...
CVE-2023-48882MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-48881MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-48880MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-49090MEDIUM6.1CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-T...
CVE-2023-49674MEDIUM4.3A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Over...
CVE-2023-49653MEDIUM6.5Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers wit...
CVE-2023-6070MEDIUM4.3 A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user t...
CVE-2023-49092MEDIUM5.9RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information abo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now