2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40178MEDIUM5.3Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp...
CVE-2023-40176MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered ...
CVE-2023-20234MEDIUM6A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overw...
CVE-2023-20230MEDIUM5.4A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (...
CVE-2023-20200MEDIUM6.3A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Serie...
CVE-2023-20168MEDIUM6.5A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc...
CVE-2023-20115MEDIUM5.4A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in stand...
CVE-2023-39441MEDIUM5.9Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 ar...
CVE-2023-32509MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 ...
CVE-2023-32505MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions.
CVE-2023-32300MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
CVE-2023-28994MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions.
CVE-2023-32499MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tony Zeoli, Tony Hayes Radio Station by netmix® – Manage a...
CVE-2023-32498MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Easy Form team Easy Form by AYS plugin <= 1.2.0 versio...
CVE-2023-32497MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 version...
CVE-2023-32496MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers...
CVE-2023-32236MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking C...
CVE-2023-4042MEDIUM5.5A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisor...
CVE-2023-32119MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin ...
CVE-2023-41104MEDIUM6.5libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access dur...
CVE-2023-41100MEDIUM5.3An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check ...
CVE-2023-41098MEDIUM6.1An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via th...
CVE-2023-40282MEDIUM5.4Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in t...
CVE-2023-39986MEDIUM5.5** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Read vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to...
CVE-2023-40370MEDIUM5.3 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script conten...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now