2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5412MEDIUM6.5The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcod...
CVE-2023-46210MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions.
CVE-2023-46451MEDIUM5.4Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
CVE-2023-46361MEDIUM6.5Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.
CVE-2023-46040MEDIUM5.4Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a...
CVE-2023-5867MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5866MEDIUM5.7Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
CVE-2023-5864MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
CVE-2023-5863MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5861MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-31794MEDIUM5.5MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability al...
CVE-2023-46139MEDIUM5.7KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelS...
CVE-2023-46138MEDIUM5.3JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr...
CVE-2023-45671MEDIUM4.7Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site script...
CVE-2023-45670MEDIUM6.8Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the `config/save` and `config/set` end...
CVE-2023-43798MEDIUM5.4BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable t...
CVE-2023-43797MEDIUM5.4BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable...
CVE-2023-43648MEDIUM6.5baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the...
CVE-2023-43647MEDIUM5.4baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in th...
CVE-2023-42804MEDIUM5.3BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vuln...
CVE-2023-40101MEDIUM5.5In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2023-21395MEDIUM6.5In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disc...
CVE-2023-21394MEDIUM5.5In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a ...
CVE-2023-21387MEDIUM4.4In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log inform...
CVE-2023-21385MEDIUM5.5In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information di...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now