2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39338MEDIUM6.8Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized ...
CVE-2023-38329MEDIUM6.1An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in cale...
CVE-2023-38327MEDIUM5.3An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php...
CVE-2023-50458MEDIUM4.3In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
CVE-2023-43039MEDIUM6.1IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2023-50786MEDIUM4.3Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded ...
CVE-2023-47310MEDIUM6.5A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute...
CVE-2023-29113MEDIUM6.3The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the p...
CVE-2023-28912MEDIUM5.7The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution ...
CVE-2023-28911MEDIUM6.5A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper va...
CVE-2023-28908MEDIUM5.4A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper va...
CVE-2023-28907MEDIUM6.7There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the...
CVE-2023-28904MEDIUM5.2A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attack...
CVE-2023-38007MEDIUM5.4IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4....
CVE-2023-47298MEDIUM4.3An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoi...
CVE-2023-45256MEDIUM5.4Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow ...
CVE-2023-48786MEDIUM4.3A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before ...
CVE-2023-26002MEDIUM4.3Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control...
CVE-2023-26001MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design N...
CVE-2023-26000MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hanhdo205 Bang tin...
CVE-2023-25997MEDIUM6.5Missing Authorization vulnerability in SolaPlugins Sola Support Ticket allows Exploiting Incorrectly Configured Access C...
CVE-2023-53154MEDIUM5.5parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars...
CVE-2023-33861MEDIUM6.5IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication pat...
CVE-2023-7230MEDIUM6.1The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users ...
CVE-2023-7229MEDIUM5.5The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which co...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now