2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2026MEDIUM4.8The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high...
CVE-2023-29256MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information d...
CVE-2023-28955MEDIUM6.5IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted reques...
CVE-2023-28953MEDIUM4.3IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the se...
CVE-2023-23487MEDIUM4.3IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logg...
CVE-2023-1780MEDIUM6.1The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before output...
CVE-2023-1183MEDIUM5.5A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCR...
CVE-2023-1119MEDIUM6.1The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library th...
CVE-2023-3552MEDIUM5.4Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
CVE-2023-32000MEDIUM4.8A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor ...
CVE-2023-37269MEDIUM4.8Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backen...
CVE-2023-20180MEDIUM4.3A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct ...
CVE-2023-20133MEDIUM5.4A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a ...
CVE-2023-36256MEDIUM6.5The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacke...
CVE-2023-3544MEDIUM6.1A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vu...
CVE-2023-3543MEDIUM6.1A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. Th...
CVE-2023-37264MEDIUM4.3Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, p...
CVE-2023-37067MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups managemen...
CVE-2023-37066MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
CVE-2023-37065MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management ...
CVE-2023-37064MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management sect...
CVE-2023-37063MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions managem...
CVE-2023-37062MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definitio...
CVE-2023-37061MEDIUM4.8Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management sect...
CVE-2023-3542MEDIUM6.1A vulnerability was found in ThinuTech ThinuCMS 1.5 and classified as problematic. Affected by this issue is some unknow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now