2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-47217MEDIUM5.5in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.
CVE-2023-46705MEDIUM5.5in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.
CVE-2023-46100MEDIUM5.5in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitia...
CVE-2023-42774MEDIUM5.5in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default ...
CVE-2023-3379MEDIUM5.3Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to chan...
CVE-2023-47175MEDIUM6.1Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior ...
CVE-2023-5341MEDIUM5.5A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
CVE-2023-48736MEDIUM6.5In International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-o...
CVE-2023-40363MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect f...
CVE-2023-40817MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
CVE-2023-40816MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
CVE-2023-40815MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
CVE-2023-40814MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
CVE-2023-40813MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.
CVE-2023-40812MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
CVE-2023-40810MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
CVE-2023-40809MEDIUM6.1OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
CVE-2023-44796MEDIUM5.4Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate ...
CVE-2023-48294MEDIUM4.3LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2023-48295MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2023-48024MEDIUM6.5Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_...
CVE-2023-44355MEDIUM4.3Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu...
CVE-2023-44352MEDIUM6.1Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scriptin...
CVE-2023-26364MEDIUM5.3@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result ...
CVE-2023-22268MEDIUM6.5Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now