2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-34916MEDIUM6.1Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
CVE-2023-38311MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System ...
CVE-2023-38310MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configu...
CVE-2023-38309MEDIUM6.1An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the pack...
CVE-2023-38308MEDIUM6.1An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel fu...
CVE-2023-38307MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a...
CVE-2023-38306MEDIUM6.1An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file up...
CVE-2023-38305MEDIUM6.1An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting...
CVE-2023-38304MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a...
CVE-2023-38303MEDIUM5.4An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Co...
CVE-2023-35792MEDIUM6.1Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS).
CVE-2023-35791MEDIUM6.1Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
CVE-2023-34872MEDIUM5.5A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (...
CVE-2023-3508MEDIUM6.5The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which ...
CVE-2023-3507MEDIUM6.5The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could ...
CVE-2023-3345MEDIUM6.5The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoi...
CVE-2023-3292MEDIUM6.1The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outp...
CVE-2023-3134MEDIUM6.1The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form field...
CVE-2023-3130MEDIUM4.8The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-0602MEDIUM6.1The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the...
CVE-2023-34360MEDIUM5.4A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U run...
CVE-2023-24971MEDIUM6.5 IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to caus...
CVE-2023-22595MEDIUM5.4IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-sit...
CVE-2023-4007MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
CVE-2023-35016MEDIUM6.5IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the syste...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now