2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-45003MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media N...
CVE-2023-5522MEDIUM4.3Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w...
CVE-2023-5339MEDIUM5.5Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin...
CVE-2023-45005MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions.
CVE-2023-44990MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Mana...
CVE-2023-44311MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplica...
CVE-2023-44310MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP...
CVE-2023-44309MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7....
CVE-2023-42629MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, ...
CVE-2023-24385MEDIUM4.8Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 ...
CVE-2023-42497MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through ...
CVE-2023-45358MEDIUM5.4Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote...
CVE-2023-45357MEDIUM6.5Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authen...
CVE-2023-34209MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHu...
CVE-2023-34208MEDIUM6.5Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated us...
CVE-2023-38719MEDIUM4.4IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation ...
CVE-2023-45807MEDIUM5.4OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 202...
CVE-2023-45540MEDIUM6.5An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted s...
CVE-2023-44394MEDIUM4.3MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user c...
CVE-2023-44391MEDIUM5.3Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh...
CVE-2023-43659MEDIUM5.4Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc...
CVE-2023-43658MEDIUM6.1dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i...
CVE-2023-45542MEDIUM6.1Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a cra...
CVE-2023-40851MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin p...
CVE-2023-5561MEDIUM5.3WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attacke...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now