2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39067MEDIUM6.1Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a cra...
CVE-2023-41000MEDIUM5.5GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder....
CVE-2023-4630MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting fr...
CVE-2023-40786MEDIUM5.4HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.
CVE-2023-36980MEDIUM5.3An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casin...
CVE-2023-4581MEDIUM4.3Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be down...
CVE-2023-4580MEDIUM6.5Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sen...
CVE-2023-4578MEDIUM6.5When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErro...
CVE-2023-4577MEDIUM6.5When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to...
CVE-2023-4575MEDIUM6.5When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been cre...
CVE-2023-4574MEDIUM6.5When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been cr...
CVE-2023-4104MEDIUM5.5An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user ...
CVE-2023-4573MEDIUM6.5When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a u...
CVE-2023-35845MEDIUM4.7Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file use...
CVE-2023-40040MEDIUM5.3An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacke...
CVE-2023-42467MEDIUM5.5QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_...
CVE-2023-4879MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
CVE-2023-4878MEDIUM5.4Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4870MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Contact Manager App 1.0. This affects an unkn...
CVE-2023-4864MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Take-Note App 1.0. This affects an unk...
CVE-2023-4875MEDIUM5.7Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
CVE-2023-4874MEDIUM6.5Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
CVE-2023-4847MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Simple Book Catalog App 1.0. Affected is an u...
CVE-2023-4838MEDIUM5.4The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2023-41564MEDIUM6.1An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute ar...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now