2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29546MEDIUM6.5When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden,...
CVE-2023-29545MEDIUM6.5Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable n...
CVE-2023-0489MEDIUM5.4The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0368MEDIUM5.4The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate ...
CVE-2023-32210MEDIUM6.5Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately priv...
CVE-2023-32208MEDIUM5.3Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.
CVE-2023-29532MEDIUM5.5A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service...
CVE-2023-35005MEDIUM6.5In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerabi...
CVE-2023-35866MEDIUM5.5In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master passwo...
CVE-2023-35862MEDIUM6.5libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.
CVE-2023-34657MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or...
CVE-2023-35840MEDIUM6.5_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVol...
CVE-2023-3311MEDIUM5.4A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. T...
CVE-2023-3309MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu...
CVE-2023-34459MEDIUM5.9OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2...
CVE-2023-35789MEDIUM5.5An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only ...
CVE-2023-33438MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to injec...
CVE-2023-30904MEDIUM5.5A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information...
CVE-2023-30903MEDIUM5.5HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6...
CVE-2023-3195MEDIUM5.5A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the ...
CVE-2023-34475MEDIUM5.5A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attac...
CVE-2023-34474MEDIUM5.5A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A loca...
CVE-2023-34660MEDIUM6.5jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
CVE-2023-34733MEDIUM6.8A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers...
CVE-2023-30453MEDIUM5.4The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now