2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-43786MEDIUM5.5A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local ...
CVE-2023-43785MEDIUM5.5A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows ...
CVE-2023-43485MEDIUM5.5 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audi...
CVE-2023-41964MEDIUM6.5 The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Sof...
CVE-2023-41253MEDIUM5.5 When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintex...
CVE-2023-39447MEDIUM4.4 When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log....
CVE-2023-44763MEDIUM5.4Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cros...
CVE-2023-44315MEDIUM5.4A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes ce...
CVE-2023-43623MEDIUM5.3A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix For...
CVE-2023-38640MEDIUM4.4A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is instal...
CVE-2023-37195MEDIUM4.4A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (...
CVE-2023-37194MEDIUM6.7A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (...
CVE-2023-5498MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.
CVE-2023-5468MEDIUM5.4The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in ...
CVE-2023-5467MEDIUM5.4The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,...
CVE-2023-44826MEDIUM5.4Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a cra...
CVE-2023-42477MEDIUM6.5SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a v...
CVE-2023-42475MEDIUM4.3The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker...
CVE-2023-42474MEDIUM5.4SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The...
CVE-2023-42473MEDIUM5.4S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticat...
CVE-2023-41365MEDIUM4.3SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault me...
CVE-2023-44813MEDIUM6.1Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c...
CVE-2023-44812MEDIUM6.1Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c...
CVE-2023-5461MEDIUM5.9A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unkno...
CVE-2023-44821MEDIUM5.5Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denia...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now