2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38344MEDIUM6.5An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFil...
CVE-2023-41991MEDIUM5.5A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal...
CVE-2023-42806MEDIUM6.5Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{ci...
CVE-2023-42458MEDIUM5.4Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin...
CVE-2023-41048MEDIUM5.4plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten...
CVE-2023-40183MEDIUM5.3DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability ...
CVE-2023-43309MEDIUM4.8There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input ...
CVE-2023-4753MEDIUM5.5OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the err...
CVE-2023-5104MEDIUM6.5Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.
CVE-2023-4292MEDIUM5.3Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a SQL injection v...
CVE-2023-39252MEDIUM5.9 Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated a...
CVE-2023-36234MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in d...
CVE-2023-38876MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex...
CVE-2023-38875MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex...
CVE-2023-22024MEDIUM5.5In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6...
CVE-2023-42334MEDIUM6.5An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalat...
CVE-2023-40930MEDIUM6.8An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mount...
CVE-2023-39052MEDIUM6.5An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted m...
CVE-2023-39045MEDIUM6.5An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send cra...
CVE-2023-38718MEDIUM5.3IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, ...
CVE-2023-43377MEDIUM5.4A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers...
CVE-2023-43376MEDIUM5.4A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute a...
CVE-2023-40368MEDIUM4.4IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the admi...
CVE-2023-39041MEDIUM6.5An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted mess...
CVE-2023-40618MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now