2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-41687MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Irina Sokolovskaya Goods Catalog plugin <= 2.4.1...
CVE-2023-41666MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Stockdio Stock Quotes List plugin <= 2.9.9 versi...
CVE-2023-41663MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 ve...
CVE-2023-41662MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
CVE-2023-41661MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plug...
CVE-2023-41658MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry ...
CVE-2023-41657MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.
CVE-2023-41655MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Andreas Heigl authLdap plugin <= 2.5.9 versions.
CVE-2023-39308MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions.
CVE-2023-43944MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows atta...
CVE-2023-5259MEDIUM4.9A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /ad...
CVE-2023-5257MEDIUM5.7A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this is...
CVE-2023-5196MEDIUM6.5Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really lo...
CVE-2023-5195MEDIUM5.4Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete ot...
CVE-2023-5194MEDIUM4.3Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manag...
CVE-2023-5198MEDIUM4.3An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16...
CVE-2023-4532MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting fr...
CVE-2023-44469MEDIUM4.3A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated rem...
CVE-2023-3979MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting fr...
CVE-2023-3920MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting fr...
CVE-2023-3914MEDIUM5.3A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4...
CVE-2023-3115MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3...
CVE-2023-2233MEDIUM4.3An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16....
CVE-2023-0989MEDIUM5.7An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior t...
CVE-2023-26148MEDIUM5.3All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set requ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now