2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37301MEDIUM5.3An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity...
CVE-2023-37300MEDIUM5.3An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorr...
CVE-2023-34840MEDIUM6.1angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-37299MEDIUM6.1Joplin before 2.11.5 allows XSS via an AREA element of an image map.
CVE-2023-37298MEDIUM6.1Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
CVE-2023-33276MEDIUM6.1The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status ...
CVE-2023-3479MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
CVE-2023-3477MEDIUM6.1A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects ...
CVE-2023-3476MEDIUM6.1A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects ...
CVE-2023-3475MEDIUM6.1A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is ...
CVE-2023-3474MEDIUM6.1A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulne...
CVE-2023-28387MEDIUM5.5"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard...
CVE-2023-32620MEDIUM6.5Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attack...
CVE-2023-32608MEDIUM6.5Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions...
CVE-2023-32607MEDIUM5.4Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier...
CVE-2023-33336MEDIUM4.8Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbit...
CVE-2023-3469MEDIUM4.8Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.
CVE-2023-36146MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
CVE-2023-3465MEDIUM6.1A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected b...
CVE-2023-3464MEDIUM6.1A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected...
CVE-2023-36607MEDIUM5.3The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could...
CVE-2023-36471MEDIUM5.4Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki...
CVE-2023-26966MEDIUM5.5libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and...
CVE-2023-25433MEDIUM5.5libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size aft...
CVE-2023-36484MEDIUM6.1ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now