2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-30734MEDIUM5.5Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive...
CVE-2023-30731MEDIUM4.6Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to ins...
CVE-2023-5357MEDIUM5.4The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions...
CVE-2023-5291MEDIUM5.4The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in vers...
CVE-2023-3213MEDIUM5.3The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-35905MEDIUM5.4IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2023-43953MEDIUM5.4SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
CVE-2023-43952MEDIUM5.4SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management comp...
CVE-2023-43951MEDIUM5.4SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.
CVE-2023-43898MEDIUM5.5Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulne...
CVE-2023-40519MEDIUM6.1A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized...
CVE-2023-4732MEDIUM4.7A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker...
CVE-2023-34970MEDIUM4.7A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bou...
CVE-2023-33200MEDIUM4.7A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the sys...
CVE-2023-4564MEDIUM4.8This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter wi...
CVE-2023-3196MEDIUM4.8This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page de...
CVE-2023-4886MEDIUM4.4A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain...
CVE-2023-4885MEDIUM5.9Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communication...
CVE-2023-39158MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 version...
CVE-2023-2544MEDIUM6.5Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an ...
CVE-2023-5353MEDIUM6.5Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-42508MEDIUM6.5JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi...
CVE-2023-40212MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versio...
CVE-2023-40198MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions.
CVE-2023-40009MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now