2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38745MEDIUM6.3Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input...
CVE-2023-32639MEDIUM5.5Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a spec...
CVE-2023-23568MEDIUM5.4 Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view P...
CVE-2023-33777MEDIUM5.3An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversa...
CVE-2023-25074MEDIUM5.4 Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view C...
CVE-2023-22428MEDIUM6.5 Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This...
CVE-2023-20593MEDIUM5.5An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access s...
CVE-2023-37613MEDIUM6.1A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary w...
CVE-2023-3323MEDIUM5.4 A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the ...
CVE-2023-3750MEDIUM5.3A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulti...
CVE-2023-3745MEDIUM5.5A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue ...
CVE-2023-3384MEDIUM5.4A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and...
CVE-2023-3019MEDIUM6.5A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue ...
CVE-2023-33952MEDIUM6.7A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. Th...
CVE-2023-33951MEDIUM5.3A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling o...
CVE-2023-2860MEDIUM4.4An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within ...
CVE-2023-3863MEDIUM4.1A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allo...
CVE-2023-3344MEDIUM4.8The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its set...
CVE-2023-3248MEDIUM4.8The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, wh...
CVE-2023-2309MEDIUM6.1The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a...
CVE-2023-38058MEDIUM4.3An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated at...
CVE-2023-38057MEDIUM5.4An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswe...
CVE-2023-3862MEDIUM4.7A vulnerability was found in Travelmate Travelable Trek Management Solution 1.0. It has been rated as problematic. Affec...
CVE-2023-3861MEDIUM6.1A vulnerability was found in phpscriptpoint Insurance 1.2. It has been declared as problematic. Affected by this vulnera...
CVE-2023-3860MEDIUM6.1A vulnerability was found in phpscriptpoint Insurance 1.2. It has been classified as problematic. Affected is an unknown...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now