2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40306MEDIUM6.1SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a maliciou...
CVE-2023-24965MEDIUM5.3IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM...
CVE-2023-41318MEDIUM5.4matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected vers...
CVE-2023-32332MEDIUM5.4IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection...
CVE-2023-41575MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 a...
CVE-2023-41338MEDIUM5.3Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properl...
CVE-2023-39712MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-28010MEDIUM5.3In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target fu...
CVE-2023-4843MEDIUM4.8Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busines...
CVE-2023-39319MEDIUM6.1The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" ...
CVE-2023-39318MEDIUM6.1The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <sc...
CVE-2023-39676MEDIUM6.1FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi...
CVE-2023-39076MEDIUM4.6Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (bui...
CVE-2023-4777MEDIUM4.3 An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with g...
CVE-2023-41775MEDIUM5.5Improper access control vulnerability in 'direct' Desktop App for macOS ver 2.6.0 and earlier allows a local attacker to...
CVE-2023-34041MEDIUM5.3Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthent...
CVE-2023-32470MEDIUM5.5 Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulner...
CVE-2023-37367MEDIUM5.3An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Ex...
CVE-2023-40584MEDIUM6.5Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug wher...
CVE-2023-41646MEDIUM5.3Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the ...
CVE-2023-41161MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary w...
CVE-2023-41316MEDIUM5.4Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi...
CVE-2023-20194MEDIUM4.9A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the...
CVE-2023-20193MEDIUM6.7A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, ...
CVE-2023-37798MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now