2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38697MEDIUM5.3protocol-http1 provides a low-level implementation of the HTTP/1 protocol. RFC 9112 Section 7.1 defined the format of ch...
CVE-2023-38695MEDIUM6.5cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possib...
CVE-2023-38332MEDIUM6.5Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitiv...
CVE-2023-0264MEDIUM5A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authen...
CVE-2023-39112MEDIUM6.5ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
CVE-2023-38691MEDIUM6.5matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 a...
CVE-2023-38964MEDIUM6.1Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-38686MEDIUM5.3Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email...
CVE-2023-4135MEDIUM6.5A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate a...
CVE-2023-34038MEDIUM5.3VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be abl...
CVE-2023-34037MEDIUM5.3VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able...
CVE-2023-4002MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting...
CVE-2023-39343MEDIUM4.3Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form...
CVE-2023-38991MEDIUM5.4An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbi...
CVE-2023-36159MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers...
CVE-2023-36158MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run...
CVE-2023-36141MEDIUM5.3User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, w...
CVE-2023-36138MEDIUM6.1PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview...
CVE-2023-36137MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduli...
CVE-2023-37501MEDIUM6.1A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user...
CVE-2023-37500MEDIUM6.1A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacke...
CVE-2023-37499MEDIUM6.1A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An a...
CVE-2023-30958MEDIUM6.1A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundr...
CVE-2023-30952MEDIUM4.3A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the...
CVE-2023-30951MEDIUM6.5The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now