2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5153MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-8000 up to 20...
CVE-2023-5152MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 and...
CVE-2023-41872MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.
CVE-2023-41949MEDIUM4.8Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Avirtum iFolders plugin <= 1.5.0 versions.
CVE-2023-41948MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0...
CVE-2023-41874MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin...
CVE-2023-5142MEDIUM5.3A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, ...
CVE-2023-1636MEDIUM5A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that ut...
CVE-2023-1633MEDIUM5.5A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the con...
CVE-2023-1625MEDIUM5An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the...
CVE-2023-5134MEDIUM4.3The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode ...
CVE-2023-5125MEDIUM5.4The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in...
CVE-2023-43640MEDIUM6.5TaxonWorks is a web-based workbench designed for taxonomists and biodiversity scientists. Prior to version 0.34.0, a SQL...
CVE-2023-42812MEDIUM4.3Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side re...
CVE-2023-42811MEDIUM5.5aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES...
CVE-2023-23766MEDIUM6.5An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa...
CVE-2023-4774MEDIUM5.4The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik...
CVE-2023-4716MEDIUM5.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor...
CVE-2023-43782MEDIUM5.5Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if ...
CVE-2023-43771MEDIUM5.5In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.
CVE-2023-43770MEDIUM6.1Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft...
CVE-2023-43090MEDIUM5.5A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows...
CVE-2023-43763MEDIUM6.1Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manag...
CVE-2023-41616MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 ...
CVE-2023-41614MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now