2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5381MEDIUM4.8The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver...
CVE-2023-4723MEDIUM5.3The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and...
CVE-2023-4690MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2023-4689MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2023-48200MEDIUM5.4Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensiti...
CVE-2023-48198MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy ...
CVE-2023-48197MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to...
CVE-2023-6105MEDIUM5.5An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys bein...
CVE-2023-47636MEDIUM5.3The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable th...
CVE-2023-41699MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (...
CVE-2023-48219MEDIUM6.1TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM...
CVE-2023-48088MEDIUM5.4xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
CVE-2023-48087MEDIUM5.4xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/l...
CVE-2023-5676MEDIUM5.9In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentatio...
CVE-2023-4602MEDIUM6.1The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in ...
CVE-2023-46672MEDIUM5.5An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstanc...
CVE-2023-6133MEDIUM4.9The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for...
CVE-2023-4889MEDIUM5.4The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in version...
CVE-2023-47446MEDIUM5.4Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname param...
CVE-2023-41597MEDIUM6.1EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/t...
CVE-2023-6032MEDIUM5.3 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul...
CVE-2023-5987MEDIUM6.1 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could ca...
CVE-2023-5986MEDIUM6.1 A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading...
CVE-2023-5985MEDIUM4.8 A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise...
CVE-2023-5984MEDIUM4.9 A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be upload...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now