2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-34839MEDIUM6.8A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain priv...
CVE-2023-34838MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34837MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34836MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34835MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-26274MEDIUM5.4 IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2023-26273MEDIUM4.3IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validatio...
CVE-2023-35800MEDIUM4.3Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution ...
CVE-2023-35799MEDIUM5.5Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SE...
CVE-2023-34830MEDIUM5.4i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter...
CVE-2023-34099MEDIUM5.3Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it wa...
CVE-2023-34098MEDIUM5.3Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configura...
CVE-2023-32339MEDIUM6.1IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2023-3431MEDIUM5.3Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
CVE-2023-36002MEDIUM4.3A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an...
CVE-2023-36000MEDIUM6.5A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables ...
CVE-2023-35998MEDIUM4.6A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on ...
CVE-2023-2818MEDIUM5.5An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to...
CVE-2023-2795MEDIUM4.8The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-2743MEDIUM6.1The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it bac...
CVE-2023-2711MEDIUM4.8The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which coul...
CVE-2023-2627MEDIUM4.3The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, a...
CVE-2023-2624MEDIUM6.1The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2023-2623MEDIUM6.5The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user...
CVE-2023-2605MEDIUM6.1The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now