2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-23563MEDIUM6.5An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database c...
CVE-2023-38909MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-38908MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-38906MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200...
CVE-2023-4303MEDIUM6.1Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in ...
CVE-2023-4302MEDIUM4.3A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission t...
CVE-2023-4301MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to conn...
CVE-2023-4459MEDIUM5.5A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking s...
CVE-2023-4417MEDIUM6.5Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier ...
CVE-2023-4456MEDIUM6.5A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This is...
CVE-2023-3954MEDIUM6.1The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before...
CVE-2023-3936MEDIUM6.1The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2023-3667MEDIUM4.8The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-3366MEDIUM4.3The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipme...
CVE-2023-39094MEDIUM5.4Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code vi...
CVE-2023-3481MEDIUM6.1Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS...
CVE-2023-4455MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
CVE-2023-4454MEDIUM5.7Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
CVE-2023-4453MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
CVE-2023-40068MEDIUM5.4Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro vers...
CVE-2023-39543MEDIUM6.1Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior ...
CVE-2023-4439MEDIUM5.3A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by...
CVE-2023-36674MEDIUM5.3An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40...
CVE-2023-4451MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
CVE-2023-4435MEDIUM5.5Improper Input Validation in GitHub repository hamza417/inure prior to build88.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now