2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-26147MEDIUM6.1All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to...
CVE-2023-26146MEDIUM6.1All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name...
CVE-2023-3775MEDIUM4.9A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac...
CVE-2023-44174MEDIUM5.4Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability. ...
CVE-2023-44173MEDIUM5.4Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability....
CVE-2023-41911MEDIUM5.5Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).
CVE-2023-43323MEDIUM6.5mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP a...
CVE-2023-43664MEDIUM4.3PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list a...
CVE-2023-43663MEDIUM4.3PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled ...
CVE-2023-43657MEDIUM6.1discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry...
CVE-2023-43884MEDIUM5.4A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attacke...
CVE-2023-43879MEDIUM4.8Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafte...
CVE-2023-43878MEDIUM5.4Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ...
CVE-2023-43876MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary w...
CVE-2023-5215MEDIUM6.5A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-...
CVE-2023-43874MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code ...
CVE-2023-43873MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a c...
CVE-2023-43872MEDIUM5.4A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Sit...
CVE-2023-43871MEDIUM5.4A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scriptin...
CVE-2023-42756MEDIUM4.7A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SW...
CVE-2023-5233MEDIUM5.4The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode ...
CVE-2023-5232MEDIUM5.4The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in ve...
CVE-2023-5230MEDIUM5.4The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wish...
CVE-2023-44276MEDIUM5.4OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
CVE-2023-44275MEDIUM5.4OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now