2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37489MEDIUM5.3Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version ...
CVE-2023-32005MEDIUM5.3A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the...
CVE-2023-38878MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a rem...
CVE-2023-35683MEDIUM5.5In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injec...
CVE-2023-35680MEDIUM5.5In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. Thi...
CVE-2023-35679MEDIUM5.5In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead ...
CVE-2023-35677MEDIUM5.5In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission c...
CVE-2023-35675MEDIUM5.5In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files play...
CVE-2023-35671MEDIUM5.5In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read th...
CVE-2023-35664MEDIUM5.5In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2023-4318MEDIUM4.3The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers t...
CVE-2023-4307MEDIUM4.3The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, ...
CVE-2023-4294MEDIUM6.1The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing a...
CVE-2023-4270MEDIUM6.1The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in th...
CVE-2023-4060MEDIUM4.8The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-4022MEDIUM4.8The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-41336MEDIUM6.5ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s...
CVE-2023-3510MEDIUM5.4The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and i...
CVE-2023-3170MEDIUM4.8The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do...
CVE-2023-3169MEDIUM6.1The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do...
CVE-2023-2705MEDIUM6.1The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2023-41103MEDIUM5.4Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a...
CVE-2023-40032MEDIUM5.5libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libv...
CVE-2023-41609MEDIUM6.1An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim us...
CVE-2023-41593MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now