2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29046MEDIUM4.3Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, ins...
CVE-2023-29045MEDIUM5.4Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. ...
CVE-2023-29044MEDIUM5.4Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be inje...
CVE-2023-29043MEDIUM6.1Presentations may contain references to images, which are user-controlled, and could include malicious script code that ...
CVE-2023-26456MEDIUM5.4Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before ...
CVE-2023-46475MEDIUM5.4A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the ...
CVE-2023-43193MEDIUM6.1Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the fo...
CVE-2023-3164MEDIUM5.5A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/t...
CVE-2023-5917MEDIUM6.1A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the funct...
CVE-2023-5916MEDIUM4.3A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /...
CVE-2023-43087MEDIUM6.5 Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privilege...
CVE-2023-43076MEDIUM6.5 Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker...
CVE-2023-5876MEDIUM5.3Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro...
CVE-2023-5875MEDIUM5.3Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi...
CVE-2023-5606MEDIUM4.8The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9...
CVE-2023-46595MEDIUM5.4Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain cre...
CVE-2023-46327MEDIUM5.9Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a fa...
CVE-2023-5910MEDIUM6.1A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing o...
CVE-2023-45203MEDIUM6.1Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.p...
CVE-2023-45202MEDIUM6.1Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.ph...
CVE-2023-44954MEDIUM5.4Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID ...
CVE-2023-46448MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to ...
CVE-2023-45201MEDIUM6.1Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.p...
CVE-2023-3397MEDIUM6.3A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different ...
CVE-2023-1193MEDIUM6.5A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now