2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-34106MEDIUM6.5GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8...
CVE-2023-33335MEDIUM6.1Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbi...
CVE-2023-25399MEDIUM5.5A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() f...
CVE-2023-3515MEDIUM4.4Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
CVE-2023-35978MEDIUM6.1A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (X...
CVE-2023-35977MEDIUM6.5Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line ...
CVE-2023-35976MEDIUM6.5Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line ...
CVE-2023-35971MEDIUM6.1A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct ...
CVE-2023-2538MEDIUM4.2A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 ...
CVE-2023-3482MEDIUM6.5When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using...
CVE-2023-3336MEDIUM5.3TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may all...
CVE-2023-37210MEDIUM6.5A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confus...
CVE-2023-37206MEDIUM6.5Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a ...
CVE-2023-37205MEDIUM6.5The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefo...
CVE-2023-37204MEDIUM6.5A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive...
CVE-2023-37207MEDIUM6.5A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, s...
CVE-2023-34150MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
CVE-2023-35786MEDIUM4.9Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
CVE-2023-33201MEDIUM5.3Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applic...
CVE-2023-3506MEDIUM6.1A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulner...
CVE-2023-3505MEDIUM6.1A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the f...
CVE-2023-3139MEDIUM6.1The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL...
CVE-2023-2333MEDIUM6.1The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin t...
CVE-2023-2324MEDIUM6.1The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPr...
CVE-2023-2321MEDIUM6.1The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now