2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4376MEDIUM4.8The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and e...
CVE-2023-2995MEDIUM4.8The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2023-43566MEDIUM5.4In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
CVE-2023-42452MEDIUM5.4Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versi...
CVE-2023-38353MEDIUM5.9MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to...
CVE-2023-4095MEDIUM5.3User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an a...
CVE-2023-4093MEDIUM6.1Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerabil...
CVE-2023-41834MEDIUM6.1Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allo...
CVE-2023-23957MEDIUM5.4An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
CVE-2023-5054MEDIUM5.3The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi...
CVE-2023-42399MEDIUM6.1Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensiti...
CVE-2023-5060MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
CVE-2023-41599MEDIUM5.3An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traver...
CVE-2023-40788MEDIUM5.3SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway res...
CVE-2023-42446MEDIUM6.5Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and pri...
CVE-2023-39056MEDIUM6.5An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted message...
CVE-2023-39049MEDIUM6.5An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted mes...
CVE-2023-39046MEDIUM6.5An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send craf...
CVE-2023-37611MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary c...
CVE-2023-42441MEDIUM5.3Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior ...
CVE-2023-39058MEDIUM6.5An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted m...
CVE-2023-39043MEDIUM6.5An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and sen...
CVE-2023-39040MEDIUM6.5An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted mes...
CVE-2023-39039MEDIUM6.5An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send craf...
CVE-2023-38582MEDIUM5.4 Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now