2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-46802MEDIUM5.5e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configurat...
CVE-2023-47272MEDIUM6.1Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used fo...
CVE-2023-47271MEDIUM5.3PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other pr...
CVE-2023-47260MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
CVE-2023-47259MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
CVE-2023-47258MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
CVE-2023-47249MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in Ic...
CVE-2023-46964MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attac...
CVE-2023-46963MEDIUM5.3An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attack...
CVE-2023-45189MEDIUM6.5A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7...
CVE-2023-47233MEDIUM4.3The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unpl...
CVE-2023-39301MEDIUM4.3A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. I...
CVE-2023-5946MEDIUM6.1The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter i...
CVE-2023-5945MEDIUM5.4The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0....
CVE-2023-5707MEDIUM5.4The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and...
CVE-2023-4592MEDIUM6.1A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability...
CVE-2023-4768MEDIUM6.1A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit...
CVE-2023-4767MEDIUM6.1A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit...
CVE-2023-4091MEDIUM6.5A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permis...
CVE-2023-46846MEDIUM5.3SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform R...
CVE-2023-42670MEDIUM6.5A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiat...
CVE-2023-5948MEDIUM5.5Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
CVE-2023-41356MEDIUM6.5NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic...
CVE-2023-41354MEDIUM5.3Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated ...
CVE-2023-45362MEDIUM4.3An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now