2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-26149MEDIUM6.1Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-inp...
CVE-2023-38873MEDIUM6.5The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also ...
CVE-2023-38871MEDIUM5.3The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login ...
CVE-2023-41447MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41446MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-5244MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-43233MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to...
CVE-2023-43191MEDIUM5.4SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comment...
CVE-2023-41453MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41451MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41448MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41445MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-4066MEDIUM5.5A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, de...
CVE-2023-40026MEDIUM4.3Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at l...
CVE-2023-44048MEDIUM5.4Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.
CVE-2023-4523MEDIUM6.1 Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which co...
CVE-2023-42822MEDIUM6.5xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked...
CVE-2023-20268MEDIUM4.7A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticate...
CVE-2023-20253MEDIUM5.5A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenti...
CVE-2023-20251MEDIUM5.3A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticat...
CVE-2023-20202MEDIUM6.5A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers coul...
CVE-2023-20179MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2023-20109MEDIUM6.6A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Soft...
CVE-2023-5197MEDIUM6.6A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-5192MEDIUM6.5Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now