2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29065MEDIUM4.3The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat ...
CVE-2023-29064MEDIUM4.3The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets ...
CVE-2023-29061MEDIUM5.2There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can pote...
CVE-2023-30588MEDIUM5.3When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect ter...
CVE-2023-29060MEDIUM5.7The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited...
CVE-2023-49078MEDIUM6.1raptor-web is a CMS for game server communities that can be used to host information and keep track of players. In versi...
CVE-2023-48121MEDIUM5.3An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 2023040...
CVE-2023-42504MEDIUM6.5An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,...
CVE-2023-45286MEDIUM5.9A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered...
CVE-2023-42505MEDIUM4.3An authenticated user with read permissions on database connections metadata could potentially access sensitive informat...
CVE-2023-42502MEDIUM5.4An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing t...
CVE-2023-48042MEDIUM6.1Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote at...
CVE-2023-6359MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could ...
CVE-2023-5981MEDIUM5.9A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from resp...
CVE-2023-4667MEDIUM4.8 The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fie...
CVE-2023-34055MEDIUM6.5In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially cra...
CVE-2023-4220MEDIUM6.1Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C...
CVE-2023-24023MEDIUM6.8Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 t...
CVE-2023-6226MEDIUM4.3The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2023-6225MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2023-48713MEDIUM5.3Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless contai...
CVE-2023-32065MEDIUM5.8OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order t...
CVE-2023-32064MEDIUM4.3OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can acce...
CVE-2023-32063MEDIUM5OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access...
CVE-2023-5960MEDIUM5.5An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.5...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now