2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4979MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.
CVE-2023-4978MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
CVE-2023-4977MEDIUM5.4 Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
CVE-2023-40986MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attacker...
CVE-2023-40985MEDIUM5.4An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scrip...
CVE-2023-40984MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to e...
CVE-2023-4680MEDIUM6.8HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even w...
CVE-2023-41592MEDIUM5.4Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-40869MEDIUM6.1Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute a...
CVE-2023-42362MEDIUM5.4An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands ...
CVE-2023-41160MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ...
CVE-2023-41159MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote a...
CVE-2023-41156MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote atta...
CVE-2023-25588MEDIUM5.5A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s...
CVE-2023-25586MEDIUM5.5A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an ...
CVE-2023-25585MEDIUM5.5A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra...
CVE-2023-4965MEDIUM4.8A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2023-4676MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro al...
CVE-2023-41588MEDIUM6.1A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scri...
CVE-2023-37739MEDIUM6.5i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
CVE-2023-32665MEDIUM5.5A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant...
CVE-2023-32611MEDIUM5.5A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause ...
CVE-2023-39286MEDIUM4.3A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an un...
CVE-2023-39285MEDIUM4.3A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an un...
CVE-2023-41010MEDIUM5.5Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.T...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now