2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32525MEDIUM6.5Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to c...
CVE-2023-30902MEDIUM5.5A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local att...
CVE-2023-35168MEDIUM6.5DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affec...
CVE-2023-35930MEDIUM5.3SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical applica...
CVE-2023-34422MEDIUM6.5A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a...
CVE-2023-34421MEDIUM6.5A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically ...
CVE-2023-33176MEDIUM6.5BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versio...
CVE-2023-2993MEDIUM6.3A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API ca...
CVE-2023-2290MEDIUM6.7A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elev...
CVE-2023-27082MEDIUM4.8Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers t...
CVE-2023-33580MEDIUM4.8Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f...
CVE-2023-29459MEDIUM6.1The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMo...
CVE-2023-28485MEDIUM5.4A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticate...
CVE-2023-29438MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= ...
CVE-2023-29437MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory pl...
CVE-2023-29435MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Zwaply Cryptocurrency All-in-One plugin <= 3.0.1...
CVE-2023-29436MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versio...
CVE-2023-29434MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin ...
CVE-2023-29430MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.
CVE-2023-29427MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia ...
CVE-2023-29424MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling pl...
CVE-2023-29423MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / R...
CVE-2023-22359MEDIUM4.3User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
CVE-2023-1620MEDIUM4.9Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de...
CVE-2023-1619MEDIUM4.9Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now