2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-20190MEDIUM5.3A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an una...
CVE-2023-4828MEDIUM4.2An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacke...
CVE-2023-4803MEDIUM4.8A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) S...
CVE-2023-4802MEDIUM4.8A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management ...
CVE-2023-39916MEDIUM6.5NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible...
CVE-2023-38215MEDIUM5.4Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2023-38214MEDIUM5.4Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2023-40715MEDIUM5.5A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an att...
CVE-2023-36638MEDIUM4.3An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0...
CVE-2023-36551MEDIUM5.3A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows at...
CVE-2023-29183MEDIUM5.4An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiP...
CVE-2023-27998MEDIUM5.3A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1...
CVE-2023-25608MEDIUM6.5An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr...
CVE-2023-4039MEDIUM4.8**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker t...
CVE-2023-29306MEDIUM6.1Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta...
CVE-2023-29305MEDIUM6.1Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta...
CVE-2023-4400MEDIUM6.5 A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x pr...
CVE-2023-4917MEDIUM6.5The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 ...
CVE-2023-4915MEDIUM5.3The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including ...
CVE-2023-4813MEDIUM5.9A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed...
CVE-2023-41423MEDIUM5.4Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code ...
CVE-2023-4909MEDIUM4.3Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfus...
CVE-2023-4908MEDIUM4.3Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to ...
CVE-2023-4907MEDIUM4.3Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to ...
CVE-2023-4906MEDIUM4.3Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now