2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3746MEDIUM5.4The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allo...
CVE-2023-3707MEDIUM4.3The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong t...
CVE-2023-3706MEDIUM4.3The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to ...
CVE-2023-3279MEDIUM4.9The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to g...
CVE-2023-29484MEDIUM6.5In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
CVE-2023-45683MEDIUM6.1github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the AC...
CVE-2023-45669MEDIUM5.3WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions ...
CVE-2023-45660MEDIUM4.3Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, t...
CVE-2023-45148MEDIUM4.3Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nex...
CVE-2023-45690MEDIUM4.9Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's aut...
CVE-2023-45689MEDIUM6.5Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux al...
CVE-2023-45688MEDIUM4.3Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an auth...
CVE-2023-5575MEDIUM6.5 Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker...
CVE-2023-46066MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Codedrafty Mediabay – Media Library Folders plugin <=...
CVE-2023-44987MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Timely - Appointment software Timely Booking Button pl...
CVE-2023-44986MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce pl...
CVE-2023-44985MEDIUM5.4Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions.
CVE-2023-44984MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robin Wilson bbp style pack plugin <= 5.6.7 vers...
CVE-2023-44229MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny Carousel Horizontal Slider plugin <...
CVE-2023-5595MEDIUM5.5Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
CVE-2023-5421MEDIUM5.5An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th...
CVE-2023-4834MEDIUM4.3In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an ...
CVE-2023-4620MEDIUM6.1The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowin...
CVE-2023-45757MEDIUM6.1Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz p...
CVE-2023-43666MEDIUM6.5Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now