2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38059MEDIUM5.3The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the pay...
CVE-2023-21414MEDIUM6.8NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection fo...
CVE-2023-40791MEDIUM6.3extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, a...
CVE-2023-5591MEDIUM6.5 SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.
CVE-2023-35013MEDIUM4.4IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive informatio...
CVE-2023-5588MEDIUM5.3A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emo...
CVE-2023-5585MEDIUM6.1A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. Th...
CVE-2023-45863MEDIUM6.4An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a r...
CVE-2023-45862MEDIUM5.5An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before ...
CVE-2023-40367MEDIUM5.4IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...
CVE-2023-45176MEDIUM5.5IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 1...
CVE-2023-5582MEDIUM5.4A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr...
CVE-2023-5581MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af...
CVE-2023-5579MEDIUM6.5A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno...
CVE-2023-1259MEDIUM5.5The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, a...
CVE-2023-5578MEDIUM5.4A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln...
CVE-2023-45348MEDIUM4.3Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve s...
CVE-2023-42792MEDIUM6.5Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim...
CVE-2023-42780MEDIUM6.5Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to...
CVE-2023-42663MEDIUM6.5Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specifi...
CVE-2023-30148MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart ...
CVE-2023-45674MEDIUM6.5Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was ...
CVE-2023-36559MEDIUM4.2Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-34977MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability co...
CVE-2023-32970MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now