2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29093MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Con...
CVE-2023-28992MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP Coupon Affiliates – WooCommerce Af...
CVE-2023-28991MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date ti...
CVE-2023-28988MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, ...
CVE-2023-36675MEDIUM6.1An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. Bloc...
CVE-2023-36662MEDIUM5.4The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affe...
CVE-2023-36666MEDIUM6.1INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, pag...
CVE-2023-3396MEDIUM6.5A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0. It has been declared as critical. Affected by t...
CVE-2023-3388MEDIUM6.1The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_...
CVE-2023-3387MEDIUM5.4The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' an...
CVE-2023-1724MEDIUM5.4Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the...
CVE-2023-35173MEDIUM6.5Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client sid...
CVE-2023-35171MEDIUM6.1NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform...
CVE-2023-35163MEDIUM5.2Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to v...
CVE-2023-35154MEDIUM6.5Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1....
CVE-2023-3212MEDIUM4.4A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file s...
CVE-2023-36346MEDIUM6.1POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame...
CVE-2023-35931MEDIUM4.3Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment...
CVE-2023-35759MEDIUM6.1In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious inp...
CVE-2023-35167MEDIUM6.3Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by...
CVE-2023-3394MEDIUM5.4Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
CVE-2023-35162MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able ...
CVE-2023-35161MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able ...
CVE-2023-35160MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able ...
CVE-2023-35159MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now