2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-43645MEDIUM5.9OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerabl...
CVE-2023-43614MEDIUM6.1Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote ...
CVE-2023-43493MEDIUM4.9SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or ...
CVE-2023-43484MEDIUM6.1Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauth...
CVE-2023-43331MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitr...
CVE-2023-43263MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the M...
CVE-2023-43232MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows at...
CVE-2023-42453MEDIUM4.3Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forg...
CVE-2023-41996MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6. Apps that fail verification che...
CVE-2023-41986MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may b...
CVE-2023-41981MEDIUM4.4The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ...
CVE-2023-41980MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom...
CVE-2023-41979MEDIUM4.7A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modi...
CVE-2023-41968MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS...
CVE-2023-41962MEDIUM6.1Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows...
CVE-2023-41904MEDIUM5.4Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
CVE-2023-41888MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41861MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions.
CVE-2023-41860MEDIUM6.1Unauth. Cross-Site Scripting (XSS) vulnerability in TravelMap plugin <= 1.0.1 versions.
CVE-2023-41653MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
CVE-2023-41323MEDIUM5.3GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41321MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41312MEDIUM5.3Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several ap...
CVE-2023-41311MEDIUM5.3Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to ...
CVE-2023-41242MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now