2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40779MEDIUM6.1An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafte...
CVE-2023-4951MEDIUM4.8A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Conf...
CVE-2023-42178MEDIUM6.5Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.
CVE-2023-38558MEDIUM5.5A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad...
CVE-2023-42503MEDIUM5.5Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi...
CVE-2023-38206MEDIUM5.3Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp...
CVE-2023-26141MEDIUM4.9Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the...
CVE-2023-4948MEDIUM4.3The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2023-4945MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in...
CVE-2023-4944MEDIUM5.4The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' short...
CVE-2023-4841MEDIUM5.4The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in ...
CVE-2023-41162MEDIUM6.1A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to...
CVE-2023-41158MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers...
CVE-2023-41155MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 all...
CVE-2023-41154MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attacker...
CVE-2023-41152MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers...
CVE-2023-40617MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execut...
CVE-2023-4568MEDIUM6.5PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to...
CVE-2023-42468MEDIUM5.3The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls ...
CVE-2023-3588MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic ...
CVE-2023-4155MEDIUM5.6A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-S...
CVE-2023-3301MEDIUM5.6A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared...
CVE-2023-3280MEDIUM5.5A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user ...
CVE-2023-3255MEDIUM6.5A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lea...
CVE-2023-20233MEDIUM6.5A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticat...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now