2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3541MEDIUM6.1A vulnerability has been found in ThinuTech ThinuCMS 1.5 and classified as problematic. Affected by this vulnerability i...
CVE-2023-29998MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated user...
CVE-2023-3540MEDIUM6.1A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected ...
CVE-2023-3539MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issu...
CVE-2023-3538MEDIUM5.4A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affect...
CVE-2023-3537MEDIUM6.1A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an un...
CVE-2023-3536MEDIUM6.1A vulnerability was found in SimplePHPscripts Funeral Script PHP 3.1. It has been rated as problematic. Affected by this...
CVE-2023-3535MEDIUM6.1A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this ...
CVE-2023-37308MEDIUM5.4Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
CVE-2023-34197MEDIUM5.4Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 ...
CVE-2023-33008MEDIUM5.3Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can...
CVE-2023-3532MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
CVE-2023-35890MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encodin...
CVE-2023-35765MEDIUM6.5 PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentia...
CVE-2023-32652MEDIUM6.1 PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cros...
CVE-2023-36829MEDIUM5.4Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2,...
CVE-2023-3531MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
CVE-2023-36462MEDIUM5.4Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versi...
CVE-2023-36459MEDIUM6.1Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to version...
CVE-2023-1298MEDIUM6.1ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was ...
CVE-2023-37454MEDIUM5.5An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write ...
CVE-2023-37453MEDIUM4.6An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in r...
CVE-2023-36823MEDIUM6.1Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak a...
CVE-2023-37136MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attac...
CVE-2023-37135MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now