2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-45394MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 ...
CVE-2023-46115MEDIUM5.5Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil...
CVE-2023-41894MEDIUM5.3Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook compone...
CVE-2023-41893MEDIUM5.4Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `clien...
CVE-2023-39731MEDIUM5.3The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send ...
CVE-2023-43340MEDIUM5.2Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a cr...
CVE-2023-45819MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notif...
CVE-2023-45818MEDIUM6.1TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM...
CVE-2023-45815MEDIUM5.4ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the...
CVE-2023-45280MEDIUM5.4Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up...
CVE-2023-45279MEDIUM5.4Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up...
CVE-2023-43875MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to ex...
CVE-2023-43359MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...
CVE-2023-43344MEDIUM5.4Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-43342MEDIUM5.4Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-43341MEDIUM6.1Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via ...
CVE-2023-45822MEDIUM5.3Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-45821MEDIUM6.3Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-30633MEDIUM5.3An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR...
CVE-2023-45826MEDIUM6.5Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files....
CVE-2023-45825MEDIUM5.5ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custo...
CVE-2023-45820MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus insta...
CVE-2023-42666MEDIUM5.3 The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnera...
CVE-2023-41088MEDIUM6.5 The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which ...
CVE-2023-40153MEDIUM6.1 The affected product is vulnerable to a cross-site scripting vulnerability, which could allow an attacker to access the...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now