2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39376MEDIUM6.5 SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
CVE-2023-39233MEDIUM6.5The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may disclos...
CVE-2023-38596MEDIUM5.5The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watch...
CVE-2023-36851MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth...
CVE-2023-35984MEDIUM4.3The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS So...
CVE-2023-34043MEDIUM6.7VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access...
CVE-2023-32421MEDIUM5.5A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app ...
CVE-2023-32361MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS ...
CVE-2023-30961MEDIUM6.1Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied a...
CVE-2023-30959MEDIUM5.4In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result i...
CVE-2023-30493MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2....
CVE-2023-30472MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 ...
CVE-2023-30471MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.7 versions.
CVE-2023-2358MEDIUM4.9 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passw...
CVE-2023-28790MEDIUM4.8Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.3 vers...
CVE-2023-28490MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versio...
CVE-2023-27628MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Webvitaly Sitekit plugin <= 1.3 versions.
CVE-2023-27622MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions...
CVE-2023-27617MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
CVE-2023-27616MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
CVE-2023-25483MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ankit Agarwal, Priyanshu Mittal Easy Coming Soon plugi...
CVE-2023-23958MEDIUM6.5Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
CVE-2023-23495MEDIUM5.5A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma ...
CVE-2023-0833MEDIUM5.5A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure ...
CVE-2023-43325MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows atta...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now