2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7339MEDIUM6.5Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This i...
CVE-2023-40693MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2....
CVE-2023-38005MEDIUM4.3IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauth...
CVE-2023-38265MEDIUM5.3IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an un...
CVE-2023-20601MEDIUM4.6Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially re...
CVE-2023-38281MEDIUM5.3IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able...
CVE-2023-38017MEDIUM5.3IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip...
CVE-2023-54343MEDIUM6.4QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to in...
CVE-2023-37525MEDIUM5.3A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF d...
CVE-2023-54341MEDIUM6.1Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to...
CVE-2023-54332MEDIUM6.1Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject ma...
CVE-2023-54328MEDIUM6.5AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes appl...
CVE-2023-53985MEDIUM6.1Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attacker...
CVE-2023-7333MEDIUM5.3A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t...
CVE-2023-52212MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issu...
CVE-2023-51513MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM F...
CVE-2023-7331MEDIUM5.1A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerabi...
CVE-2023-54321MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential null-ptr-deref in device...
CVE-2023-41656MEDIUM5.4Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Co...
CVE-2023-32238MEDIUM5.4Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): fr...
CVE-2023-40679MEDIUM6.5Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor allows Exploiting Incorrectly Configured ...
CVE-2023-32120MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bob Hostel ...
CVE-2023-28619MEDIUM4.3Missing Authorization vulnerability in bnayawpguy Resoto allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2023-52210MEDIUM5.3Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date f...
CVE-2023-53978MEDIUM5.4myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows aut...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now