2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49169MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in datafeedr.Com Ads ...
CVE-2023-50871MEDIUM4.3In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
CVE-2023-50870HIGH8.8In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
CVE-2023-49165MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins C...
CVE-2023-49160MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formzu Inc. Formzu...
CVE-2023-48765MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Till Krüss Email A...
CVE-2023-46116HIGH8.8Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati...
CVE-2023-49898HIGH7.2In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t...
CVE-2023-30867MEDIUM4.9In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fu...
CVE-2023-33222CRITICAL9.8 When handling contactless cards, usage of a specific function to get additional information from the card which...
CVE-2023-33221CRITICAL9.8 When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying...
CVE-2023-33220CRITICAL9.8 During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some att...
CVE-2023-33219CRITICAL9.8 The handler of the retrofit validation command doesn't properly check the boundaries when performing certain valida...
CVE-2023-33218CRITICAL9.8 The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This cou...
CVE-2023-6839MEDIUM5.3Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specifi...
CVE-2023-6553CRITICAL9.8The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1...
CVE-2023-48624MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-48623MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2023-48622MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-48621MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2023-48620MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-48619MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-48618MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit...
CVE-2023-48617MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit...
CVE-2023-48616MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now