2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-46058MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c...
CVE-2023-45998MEDIUM5.4kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
CVE-2023-44760MEDIUM4.8Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code ...
CVE-2023-43358MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...
CVE-2023-37636MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitr...
CVE-2023-33840MEDIUM4.8IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2023-27149MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary ...
CVE-2023-27148MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to...
CVE-2023-46288MEDIUM4.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air...
CVE-2023-38722MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulne...
CVE-2023-46331MEDIUM5.5WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fa...
CVE-2023-37532MEDIUM4.3HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files o...
CVE-2023-46332MEDIUM5.5WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
CVE-2023-43067MEDIUM6.5 Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploi...
CVE-2023-5718MEDIUM4.3The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa...
CVE-2023-46127MEDIUM5.4Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated clien...
CVE-2023-43065MEDIUM5.4 Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can expl...
CVE-2023-28804MEDIUM5.3An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing ...
CVE-2023-28803MEDIUM6.5An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on ...
CVE-2023-45802MEDIUM5.9When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were...
CVE-2023-43624MEDIUM5.5CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML externa...
CVE-2023-5702MEDIUM6.5A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue ...
CVE-2023-5701MEDIUM6.1A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerabilit...
CVE-2023-5699MEDIUM6.1A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issu...
CVE-2023-5698MEDIUM6.1A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now