2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-27429MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5....
CVE-2023-27414MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions.
CVE-2023-27450MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versio...
CVE-2023-27443MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2...
CVE-2023-27439MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions.
CVE-2023-3220MEDIUM5.5An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_...
CVE-2023-35095MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder pl...
CVE-2023-34597MEDIUM6.5A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted ...
CVE-2023-34596MEDIUM6.5A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafte...
CVE-2023-33495MEDIUM6.1Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVE-2023-35098MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 v...
CVE-2023-35097MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Internet Marketing Dojo WP Affiliate Links plugin <= 0.1.1...
CVE-2023-35882MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 ...
CVE-2023-35878MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions.
CVE-2023-26435MEDIUM5It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT doc...
CVE-2023-26434MEDIUM4.3When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26433MEDIUM4.3When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26432MEDIUM4.3When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26431MEDIUM4.3IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers wit...
CVE-2023-26429MEDIUM5.3Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected c...
CVE-2023-26428MEDIUM6.5Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same con...
CVE-2023-35884MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
CVE-2023-3315MEDIUM4.3Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission ...
CVE-2023-32659MEDIUM6.1 SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an at...
CVE-2023-3022MEDIUM5.5A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, s...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now