2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-45322MEDIUM6.5libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in ...
CVE-2023-5452MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
CVE-2023-21291MEDIUM5.5In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing p...
CVE-2023-21253MEDIUM5.5In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could ...
CVE-2023-21252MEDIUM5.5In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to imp...
CVE-2023-21244MEDIUM6.7In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che...
CVE-2023-5366MEDIUM5.5A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op...
CVE-2023-44384MEDIUM4.1Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati...
CVE-2023-23371MEDIUM4.4A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If explo...
CVE-2023-23370MEDIUM4.4An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the ...
CVE-2023-23366MEDIUM6.5A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au...
CVE-2023-23365MEDIUM6.5A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au...
CVE-2023-42445MEDIUM5.3Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when ...
CVE-2023-44771MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code ...
CVE-2023-44770MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a...
CVE-2023-44766MEDIUM4.8A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a cr...
CVE-2023-44765MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an at...
CVE-2023-44764MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installatio...
CVE-2023-44762MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute ar...
CVE-2023-44761MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 thr...
CVE-2023-44758MEDIUM5.4GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary cod...
CVE-2023-4469MEDIUM5.3The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missi...
CVE-2023-45245MEDIUM5.5Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux...
CVE-2023-45243MEDIUM5.5Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec...
CVE-2023-45242MEDIUM5.5Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now