2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36118MEDIUM5.4Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arb...
CVE-2023-34869MEDIUM6.1PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /...
CVE-2023-33564MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Boo...
CVE-2023-33560MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking C...
CVE-2023-31426MEDIUM6.5 The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 ...
CVE-2023-31429MEDIUM5.5Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “c...
CVE-2023-20583MEDIUM4.7A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU po...
CVE-2023-38560MEDIUM5.5An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local ...
CVE-2023-38559MEDIUM5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a ...
CVE-2023-36211MEDIUM5.4The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with ce...
CVE-2023-4054MEDIUM5.5When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only...
CVE-2023-4053MEDIUM6.5A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, ...
CVE-2023-4052MEDIUM6.5The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d...
CVE-2023-4049MEDIUM5.9Race conditions in reference counting code were found through code inspection. These could have resulted in potentially ...
CVE-2023-4046MEDIUM5.3In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in i...
CVE-2023-4045MEDIUM5.3Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from anot...
CVE-2023-38357MEDIUM5.3Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a...
CVE-2023-23548MEDIUM6.1Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
CVE-2023-37496MEDIUM5.4HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a vi...
CVE-2023-3462MEDIUM5.3HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker m...
CVE-2023-38989MEDIUM4.3An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrar...
CVE-2023-4010MEDIUM4.6A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a lo...
CVE-2023-3817MEDIUM5.3Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use ...
CVE-2023-37580MEDIUM6.1Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVE-2023-34917MEDIUM6.1Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now