2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3586MEDIUM5.4Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, re...
CVE-2023-3585MEDIUM4.3Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially...
CVE-2023-3582MEDIUM4.3Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated ...
CVE-2023-3577MEDIUM4.3Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an...
CVE-2023-36656MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute ...
CVE-2023-35818MEDIUM6.8An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker ...
CVE-2023-31853MEDIUM6.1Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon paramet...
CVE-2023-31851MEDIUM6.1Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via t...
CVE-2023-3245MEDIUM4.8The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could al...
CVE-2023-3182MEDIUM6.1The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-3041MEDIUM6.1The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before output...
CVE-2023-31852MEDIUM6.1Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the ifac...
CVE-2023-2960MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Ol...
CVE-2023-2701MEDIUM6.1The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, lea...
CVE-2023-2579MEDIUM5.4The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow use...
CVE-2023-2143MEDIUM5.4The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross...
CVE-2023-1893MEDIUM6.1The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the...
CVE-2023-0439MEDIUM5.4The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripti...
CVE-2023-34036MEDIUM5.3 Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious f...
CVE-2023-3700MEDIUM4.3Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-35012MEDIUM6.7IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a...
CVE-2023-35901MEDIUM5.3IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation...
CVE-2023-33857MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially craf...
CVE-2023-3691MEDIUM6.1A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown par...
CVE-2023-3685MEDIUM5.4A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now