2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-30955MEDIUM5.4A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and vi...
CVE-2023-30946MEDIUM4.3A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have...
CVE-2023-36488MEDIUM5.4ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
CVE-2023-34658MEDIUM5.3Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSa...
CVE-2023-37256MEDIUM6.1An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in ...
CVE-2023-37255MEDIUM6.1An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "g...
CVE-2023-37254MEDIUM6.1An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a c...
CVE-2023-37251MEDIUM6.1An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackur...
CVE-2023-34599MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to ex...
CVE-2023-34486MEDIUM6.1itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote co...
CVE-2023-36617MEDIUM5.3A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that ha...
CVE-2023-34834MEDIUM5.3A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attacker...
CVE-2023-34831MEDIUM5.4The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security is...
CVE-2023-34734MEDIUM4.8Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) .
CVE-2023-34648MEDIUM6.1A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v....
CVE-2023-1602MEDIUM4.8The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insuf...
CVE-2023-36476MEDIUM5.5calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of cala...
CVE-2023-33661MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRo...
CVE-2023-3359MEDIUM5.5An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the r...
CVE-2023-3358MEDIUM5.5A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a ...
CVE-2023-3357MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local use...
CVE-2023-36474MEDIUM6.1Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prio...
CVE-2023-34647MEDIUM6.1PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-3439MEDIUM4.7A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant...
CVE-2023-3355MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c code in the submit_...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now