2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39558MEDIUM6.1AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai...
CVE-2023-4611MEDIUM6.3A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is ...
CVE-2023-4296MEDIUM6.1​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to i...
CVE-2023-41153MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ...
CVE-2023-38971MEDIUM5.4Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via...
CVE-2023-32241MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5...
CVE-2023-3253MEDIUM4.3An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list...
CVE-2023-39678MEDIUM6.1A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F ...
CVE-2023-39267MEDIUM6.5An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful ...
CVE-2023-39266MEDIUM6.1A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct...
CVE-2023-3252MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges coul...
CVE-2023-3251MEDIUM4.9 A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover st...
CVE-2023-39522MEDIUM5.3goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage...
CVE-2023-41037MEDIUM4.3OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Message...
CVE-2023-39615MEDIUM6.5Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxm...
CVE-2023-24548MEDIUM6.5On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tun...
CVE-2023-38283MEDIUM5.3In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant r...
CVE-2023-0238MEDIUM5.5Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic...
CVE-2023-41363MEDIUM4.3In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other...
CVE-2023-4569MEDIUM5.5A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue ...
CVE-2023-40781MEDIUM6.5Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a cra...
CVE-2023-34725MEDIUM6.8An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated pri...
CVE-2023-34724MEDIUM6.8An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated priv...
CVE-2023-40170MEDIUM6.1jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs coul...
CVE-2023-39968MEDIUM6.1jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now