2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-42247MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.
CVE-2023-42246MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.
CVE-2023-42245MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.
CVE-2023-42243MEDIUM5.4In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php,...
CVE-2023-42234MEDIUM5.4Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView fu...
CVE-2023-42233MEDIUM6.1Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEdit...
CVE-2023-42230MEDIUM6.1Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save func...
CVE-2023-42229MEDIUM6.5Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created ...
CVE-2023-38037MEDIUM5.5ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissi...
CVE-2023-28362MEDIUM4The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value...
CVE-2023-28120MEDIUM5.3There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user inp...
CVE-2023-27539MEDIUM5.3There is a denial of service vulnerability in the header parsing component of Rack.
CVE-2023-27531MEDIUM5.3There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
CVE-2023-23913MEDIUM6.3There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML ...
CVE-2023-6604MEDIUM5.3A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentiall...
CVE-2023-6601MEDIUM4.7A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggerin...
CVE-2023-23672MEDIUM5.4Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
CVE-2023-48739MEDIUM5.3Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Inc...
CVE-2023-47807MEDIUM4.3Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured...
CVE-2023-47778MEDIUM4.3Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorre...
CVE-2023-45633MEDIUM6.5Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2023-45272MEDIUM4.3Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured ...
CVE-2023-40327MEDIUM6.5Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Con...
CVE-2023-39994MEDIUM4.3Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Acce...
CVE-2023-32240MEDIUM5.4Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now