2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-47097MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows r...
CVE-2023-47096MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin ...
CVE-2023-47095MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization...
CVE-2023-47094MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows r...
CVE-2023-46278MEDIUM6.5Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated at...
CVE-2023-46378MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted stri...
CVE-2023-39695MEDIUM5.3Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter...
CVE-2023-44484MEDIUM6.1Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstNam...
CVE-2023-39610MEDIUM6.5An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Ser...
CVE-2023-20886MEDIUM6.1VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a ...
CVE-2023-37831MEDIUM5.3An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server re...
CVE-2023-43796MEDIUM5.3Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote ...
CVE-2023-46722MEDIUM6.1The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulne...
CVE-2023-46255MEDIUM6.5SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per...
CVE-2023-46250MEDIUM5.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 ...
CVE-2023-46237MEDIUM5.3FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint...
CVE-2023-46235MEDIUM6.1FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a...
CVE-2023-5519MEDIUM4.3The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke...
CVE-2023-5458MEDIUM5.4The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG file...
CVE-2023-5307MEDIUM6.1The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, whic...
CVE-2023-5243MEDIUM4.8The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could a...
CVE-2023-5238MEDIUM6.1The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-5237MEDIUM5.4The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes be...
CVE-2023-5229MEDIUM4.8The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high priv...
CVE-2023-5211MEDIUM6.1The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now