2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37134MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to ...
CVE-2023-37133MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to ...
CVE-2023-37132MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to e...
CVE-2023-37131MEDIUM6.5A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers...
CVE-2023-37125MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers...
CVE-2023-37124MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute a...
CVE-2023-37122MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or...
CVE-2023-36970MEDIUM5.4A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web sc...
CVE-2023-35948MEDIUM6.1Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redir...
CVE-2023-30326MEDIUM6.1Cross Site Scripting (XSS) vulnerability in username field in /WebContent/WEB-INF/lib/chatbox.jsp in wliang6 ChatEngine ...
CVE-2023-30322MEDIUM5.4Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0...
CVE-2023-24497MEDIUM4.7Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN ...
CVE-2023-24496MEDIUM4.7Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN ...
CVE-2023-23547MEDIUM6.5A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A...
CVE-2023-36995MEDIUM6.1TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, ...
CVE-2023-3456MEDIUM5.3Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability ...
CVE-2023-37238MEDIUM5.3Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module....
CVE-2023-26138MEDIUM4.3All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to...
CVE-2023-26137MEDIUM6.1All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input i...
CVE-2023-30678MEDIUM5.5Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows atta...
CVE-2023-30677MEDIUM4.6Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data...
CVE-2023-30676MEDIUM4.6Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data...
CVE-2023-30675MEDIUM5.5Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account informa...
CVE-2023-30674MEDIUM6.5Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.
CVE-2023-30673MEDIUM5.5Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attack...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now