2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5797MEDIUM5.5An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t...
CVE-2023-5650MEDIUM5.5An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, ...
CVE-2023-4397MEDIUM4.4A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, US...
CVE-2023-37926MEDIUM5.5A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware ve...
CVE-2023-37925MEDIUM5.5An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t...
CVE-2023-35139MEDIUM6.1A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.3...
CVE-2023-35136MEDIUM5.5An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 throug...
CVE-2023-47437MEDIUM5.4A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting...
CVE-2023-49145MEDIUM5.4Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user ...
CVE-2023-46355MEDIUM5.3In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal informati...
CVE-2023-42366MEDIUM5.5A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
CVE-2023-42365MEDIUM5.5A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar functio...
CVE-2023-42364MEDIUM5.5A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk patte...
CVE-2023-5885MEDIUM6.5The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login...
CVE-2023-42363MEDIUM5.5A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
CVE-2023-32062MEDIUM4.3OroPlatform is a package that assists system and user calendar management. Back-office users can access information from...
CVE-2023-48034MEDIUM6.1An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless key...
CVE-2023-5958MEDIUM6.1The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the bac...
CVE-2023-5942MEDIUM5.4The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-5845MEDIUM5.3The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthentic...
CVE-2023-5738MEDIUM5.4The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could...
CVE-2023-5737MEDIUM4.3The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users wit...
CVE-2023-5653MEDIUM6.1The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers bef...
CVE-2023-5641MEDIUM6.1The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a...
CVE-2023-5620MEDIUM5.4The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now