2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32503MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.6 versions.
CVE-2023-29099MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.
CVE-2023-27422MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes NS Coupon To Become Customer plugin <= 1.2.2 ...
CVE-2023-27421MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions.
CVE-2023-27416MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Decon Digital Decon WP SMS plugin <= 1.1 versions.
CVE-2023-27412MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions.
CVE-2023-38532MEDIUM5.5A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0...
CVE-2023-21647MEDIUM6.5Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
CVE-2023-3569MEDIUM4.9In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior...
CVE-2023-39440MEDIUM4.4In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain sp...
CVE-2023-39437MEDIUM5.4SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or ap...
CVE-2023-39436MEDIUM5.8SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker t...
CVE-2023-37492MEDIUM6.5SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASI...
CVE-2023-37488MEDIUM6.1In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, ...
CVE-2023-37487MEDIUM5.3SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain op...
CVE-2023-37484MEDIUM5.3SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user prov...
CVE-2023-36926MEDIUM5.3Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente...
CVE-2023-39527MEDIUM6.1PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ...
CVE-2023-39363MEDIUM5.9Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0...
CVE-2023-38924MEDIUM6.5Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.
CVE-2023-36054MEDIUM6.5lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized poin...
CVE-2023-38157MEDIUM6.5Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-38045MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneV...
CVE-2023-3671MEDIUM6.1The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters...
CVE-2023-3650MEDIUM4.8The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now