2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36833MEDIUM6.5A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36...
CVE-2023-3434MEDIUM5.4Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. ...
CVE-2023-3433MEDIUM5.5The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts s...
CVE-2023-2975MEDIUM5.3Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries w...
CVE-2023-3672MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.
CVE-2023-3649MEDIUM5.5iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
CVE-2023-3648MEDIUM5.5Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or c...
CVE-2023-2082MEDIUM5.4The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions ...
CVE-2023-37837MEDIUM6.5libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebit...
CVE-2023-37836MEDIUM6.5libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. Thi...
CVE-2023-37275MEDIUM4.3Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GP...
CVE-2023-37272MEDIUM5.4JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation ...
CVE-2023-37849MEDIUM6.5A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute ar...
CVE-2023-37598MEDIUM4.5A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of...
CVE-2023-37468MEDIUM5.5Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LD...
CVE-2023-36473MEDIUM6.1Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X...
CVE-2023-30564MEDIUM6.9Alaris Systems Manager does not perform input validation during the Device Import Function.
CVE-2023-30562MEDIUM6.7A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
CVE-2023-30561MEDIUM6.1The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read...
CVE-2023-34458MEDIUM5.3mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a re...
CVE-2023-30560MEDIUM6.8The configuration from the PCU can be modified without authentication using physical connection to the PCU.
CVE-2023-30559MEDIUM5.7The firmware update package for the wireless card is not properly signed and can be modified.
CVE-2023-37787MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts o...
CVE-2023-37786MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts o...
CVE-2023-37785MEDIUM4.8A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now