2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36409MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-36769MEDIUM5.4Microsoft OneNote Spoofing Vulnerability
CVE-2023-45556MEDIUM5.4Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via th...
CVE-2023-5771MEDIUM6.1Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen...
CVE-2023-5605MEDIUM4.8The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2023-5530MEDIUM4.8The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could a...
CVE-2023-5354MEDIUM6.1The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2023-5352MEDIUM4.3The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing us...
CVE-2023-5228MEDIUM4.8The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could all...
CVE-2023-5181MEDIUM4.8The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow...
CVE-2023-4930MEDIUM6.5The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores a...
CVE-2023-4858MEDIUM4.8The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could a...
CVE-2023-4810MEDIUM4.8The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which coul...
CVE-2023-46732MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulner...
CVE-2023-46254MEDIUM4.3capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used...
CVE-2023-4700MEDIUM6.5An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1...
CVE-2023-46251MEDIUM6.1 MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape...
CVE-2023-40661MEDIUM6.4Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process u...
CVE-2023-40660MEDIUM6.6A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process...
CVE-2023-5969MEDIUM5.3Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially...
CVE-2023-5968MEDIUM4.9Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i...
CVE-2023-5967MEDIUM4.3Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use...
CVE-2023-5678MEDIUM5.3Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be...
CVE-2023-5950MEDIUM6.1Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerabi...
CVE-2023-5963MEDIUM4.3An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now