2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-45281MEDIUM6.1An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
CVE-2023-46033MEDIUM6.8D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The...
CVE-2023-5654MEDIUM6.5The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in ...
CVE-2023-35185MEDIUM6.8The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM pri...
CVE-2023-31046MEDIUM6.5A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditi...
CVE-2023-25753MEDIUM6.5 There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vu...
CVE-2023-34050MEDIUM4.3 In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class na...
CVE-2023-5254MEDIUM5.3The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9...
CVE-2023-5639MEDIUM5.4The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shor...
CVE-2023-5638MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode ...
CVE-2023-5336MEDIUM6.5The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's ...
CVE-2023-4645MEDIUM5.3The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v...
CVE-2023-37504MEDIUM6.5HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions ...
CVE-2023-36857MEDIUM6.5 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allo...
CVE-2023-45909MEDIUM6.1zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
CVE-2023-45958MEDIUM6.1Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pa...
CVE-2023-45814MEDIUM5.3Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So...
CVE-2023-20261MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve...
CVE-2023-5631MEDIUM5.4Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a ...
CVE-2023-45632MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions.
CVE-2023-45630MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails pl...
CVE-2023-45628MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 version...
CVE-2023-45607MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <=...
CVE-2023-45604MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 v...
CVE-2023-45602MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now