2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-47309MEDIUM5.4Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::...
CVE-2023-43588MEDIUM6.5Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disc...
CVE-2023-38544MEDIUM5.5A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. ...
CVE-2023-5189MEDIUM6.5A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball s...
CVE-2023-47518MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions.
CVE-2023-47517MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions.
CVE-2023-45627MEDIUM6.5An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulner...
CVE-2023-41570MEDIUM5.3MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
CVE-2023-39205MEDIUM6.5Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of serv...
CVE-2023-39202MEDIUM5.5Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a deni...
CVE-2023-39199MEDIUM6.5Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information di...
CVE-2023-47532MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.
CVE-2023-47528MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sajjad Hossain Sagor WP Edit Username plugin <= 1.0.5 ...
CVE-2023-47524MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and W...
CVE-2023-47522MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions.
CVE-2023-47520MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <...
CVE-2023-46581MEDIUM5.5SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name...
CVE-2023-46580MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the...
CVE-2023-46026MEDIUM4.8Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 a...
CVE-2023-46025MEDIUM4.9SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows at...
CVE-2023-46023MEDIUM6.5SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive in...
CVE-2023-36558MEDIUM5.5ASP.NET Core Security Feature Bypass Vulnerability
CVE-2023-47641MEDIUM6.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu...
CVE-2023-47549MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3....
CVE-2023-47547MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommer...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now