2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4040MEDIUM5.3The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2023-31492MEDIUM6.5Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of u...
CVE-2023-28690MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 vers...
CVE-2023-39974MEDIUM5.3Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized ac...
CVE-2023-39973MEDIUM4.3Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal ...
CVE-2023-39972MEDIUM4.3Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to cre...
CVE-2023-39971MEDIUM6.1Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla ...
CVE-2023-40168MEDIUM6.5TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to ver...
CVE-2023-36847MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthe...
CVE-2023-36846MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth...
CVE-2023-36844MEDIUM5.3A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthen...
CVE-2023-31942MEDIUM4.8Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitr...
CVE-2023-39743MEDIUM5.3lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
CVE-2023-39741MEDIUM5.5lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/l...
CVE-2023-38905MEDIUM5.5SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via th...
CVE-2023-4029MEDIUM6.7A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow ...
CVE-2023-4028MEDIUM6.7A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may...
CVE-2023-34419MEDIUM6.7A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an att...
CVE-2023-31079MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.
CVE-2023-31072MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 v...
CVE-2023-28783MEDIUM5.4Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2...
CVE-2023-28693MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin...
CVE-2023-34412MEDIUM4.8A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 ...
CVE-2023-4394MEDIUM6A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux ...
CVE-2023-31091MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now