2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37480MEDIUM4.9Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fid...
CVE-2023-28020MEDIUM6.1 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external s...
CVE-2023-35763MEDIUM5.5Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthen...
CVE-2023-33329MEDIUM4.8Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 v...
CVE-2023-33312MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <= 1.0 versions.
CVE-2023-37259MEDIUM5.4matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature i...
CVE-2023-33231MEDIUM6.1XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-0160MEDIUM5.5A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the sy...
CVE-2023-34035MEDIUM5.3Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authoriz...
CVE-2023-36384MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 ...
CVE-2023-36383MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plu...
CVE-2023-31441MEDIUM5.5In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafte...
CVE-2023-24390MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WeSecur Security plugin <= 1.2.1 versions.
CVE-2023-32965MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.
CVE-2023-2433MEDIUM5.4The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to,...
CVE-2023-3709MEDIUM5.3The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, a...
CVE-2023-3708MEDIUM6.1Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various ve...
CVE-2023-3403MEDIUM4.3The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2023-38409MEDIUM5.5An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because...
CVE-2023-37781MEDIUM6.5An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted ...
CVE-2023-37770MEDIUM5.5faust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.c...
CVE-2023-37769MEDIUM6.5stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixma...
CVE-2023-28864MEDIUM5.5Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup wor...
CVE-2023-34140MEDIUM6.5A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series fir...
CVE-2023-3593MEDIUM6.5Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now