2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-41248MEDIUM5.4In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
CVE-2023-32797MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution video carousel slider with lightbo...
CVE-2023-32603MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0...
CVE-2023-32598MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 ve...
CVE-2023-32596MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions.
CVE-2023-32595MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Sear...
CVE-2023-32575MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for Wo...
CVE-2023-24394MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup plugin <= 3.3 versions.
CVE-2023-25981MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.
CVE-2023-3425MEDIUM5.3Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS ...
CVE-2023-3406MEDIUM6.5Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS...
CVE-2023-32591MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain plugin <= 3.0.0 versions.
CVE-2023-32584MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in John Newcombe eBecas plugin <= 3.1.3 versions.
CVE-2023-32577MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versi...
CVE-2023-32576MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 v...
CVE-2023-32518MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions...
CVE-2023-32755MEDIUM5.3 e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtai...
CVE-2023-40530MEDIUM4.7Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyl...
CVE-2023-4520MEDIUM6.1The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_use...
CVE-2023-40577MEDIUM5.4Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission t...
CVE-2023-40570MEDIUM5.3Datasette is an open source multi-tool for exploring and publishing data. This bug affects Datasette instances running a...
CVE-2023-40217MEDIUM5.3An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. I...
CVE-2023-40182MEDIUM5.3Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticea...
CVE-2023-40179MEDIUM5.3Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Re...
CVE-2023-38974MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to exe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now