2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5164MEDIUM5.4The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions ...
CVE-2023-5049MEDIUM5.4The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'raf...
CVE-2023-42431MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi...
CVE-2023-45746MEDIUM5.4Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary ...
CVE-2023-46867MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a...
CVE-2023-46866MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a a...
CVE-2023-5842MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
CVE-2023-4393MEDIUM6.1HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform...
CVE-2023-46864MEDIUM5.3Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/d...
CVE-2023-46862MEDIUM4.7An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_ur...
CVE-2023-46858MEDIUM5.4Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodl...
CVE-2023-43041MEDIUM4.9IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain ...
CVE-2023-5837MEDIUM6.1A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect...
CVE-2023-46854MEDIUM6.1Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature...
CVE-2023-45897MEDIUM5.5exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.
CVE-2023-5835MEDIUM6.1A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma...
CVE-2023-46467MEDIUM5.4Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via...
CVE-2023-46490MEDIUM6.5SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actio...
CVE-2023-46211MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Pa...
CVE-2023-46209MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 version...
CVE-2023-46208MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing ...
CVE-2023-46200MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App ...
CVE-2023-40139MEDIUM5.5In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea...
CVE-2023-40133MEDIUM5.5In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu...
CVE-2023-40123MEDIUM5.5In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now