2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-41900MEDIUM4.3Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable...
CVE-2023-41889MEDIUM5.3SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalizati...
CVE-2023-41880MEDIUM5.3Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 co...
CVE-2023-41325MEDIUM6.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2023-41043MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-41042MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-40588MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-40167MEDIUM5.3Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accep...
CVE-2023-40019MEDIUM6.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-38706MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-37459MEDIUM5.3Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, ...
CVE-2023-37281MEDIUM5.3Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various...
CVE-2023-36472MEDIUM5.7Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get acce...
CVE-2023-4984MEDIUM6.5A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some un...
CVE-2023-4983MEDIUM6.1A vulnerability was found in app1pro Shopicial up to 20230830. It has been declared as problematic. This vulnerability a...
CVE-2023-4959MEDIUM6.5A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an appli...
CVE-2023-4663MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect a...
CVE-2023-32461MEDIUM6.7 Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high ...
CVE-2023-40983MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to e...
CVE-2023-4963MEDIUM5.4The WS Facebook Like Box Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likeb...
CVE-2023-40982MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or ...
CVE-2023-4973MEDIUM6.1A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerabi...
CVE-2023-4982MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
CVE-2023-4981MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
CVE-2023-4980MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now