2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39159MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions...
CVE-2023-32792MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker...
CVE-2023-32791MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker...
CVE-2023-32790MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inj...
CVE-2023-32671MEDIUM5.4A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an at...
CVE-2023-32670MEDIUM5.4Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privile...
CVE-2023-32669MEDIUM5.4Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated us...
CVE-2023-5351MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-4101MEDIUM6.5The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has suffi...
CVE-2023-4099MEDIUM6.5The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource...
CVE-2023-0828MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie val...
CVE-2023-28571MEDIUM5.5Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
CVE-2023-5334MEDIUM5.4The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsi...
CVE-2023-3335MEDIUM5.5Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local...
CVE-2023-43627MEDIUM5.7Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier...
CVE-2023-39429MEDIUM5.4Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to i...
CVE-2023-32572MEDIUM4.9A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention l...
CVE-2023-31042MEDIUM4.3A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can i...
CVE-2023-44012MEDIUM6.1Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the he...
CVE-2023-43836MEDIUM6.5There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
CVE-2023-43297MEDIUM5.4An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access toke...
CVE-2023-43267MEDIUM5.4A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to exec...
CVE-2023-44463MEDIUM5.3An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to tr...
CVE-2023-37605MEDIUM5.5Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to caus...
CVE-2023-0809MEDIUM5.3In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packet...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now