2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-43509MEDIUM5.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote ...
CVE-2023-43508MEDIUM6.5Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privi...
CVE-2023-43360MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...
CVE-2023-43281MEDIUM6.5Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a cra...
CVE-2023-42031MEDIUM4.9IBM TXSeries for Multiplatforms, 8.1, 8.2, and 9.1, CICS TX Standard CICS TX Advanced 10.1 and 11.1 could allow a privil...
CVE-2023-41721MEDIUM5.3Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and e...
CVE-2023-41339MEDIUM5.3GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS...
CVE-2023-3010MEDIUM6.1Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 ...
CVE-2023-39924MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versi...
CVE-2023-39231MEDIUM6.5PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authenti...
CVE-2023-37911MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-36085MEDIUM6.1The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdent...
CVE-2023-34447MEDIUM6.1iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, ...
CVE-2023-34446MEDIUM6.1iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pa...
CVE-2023-34085MEDIUM4.3When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user...
CVE-2023-34056MEDIUM4.3vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privil...
CVE-2023-31580MEDIUM5.9light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authen...
CVE-2023-29973MEDIUM4.9Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users ...
CVE-2023-27261MEDIUM6.5Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allow...
CVE-2023-27256MEDIUM5.3Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval ...
CVE-2023-26579MEDIUM5.3Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff inform...
CVE-2023-26577MEDIUM5.4Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the brows...
CVE-2023-25032MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Print, PDF, Email by PrintFriendly plugin <= 5.5.1 ver...
CVE-2023-1356MEDIUM6.1Reflected cross-site scripting in the StudentSearch component in IDAttend’s IDWeb application 3.1.052 and earlier allows...
CVE-2023-46059MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now