2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-35783MEDIUM6.1The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TY...
CVE-2023-20885MEDIUM6.5Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This...
CVE-2023-3294MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e1...
CVE-2023-26537MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions.
CVE-2023-26527MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
CVE-2023-25974MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
CVE-2023-3293MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
CVE-2023-27420MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions.
CVE-2023-26515MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versio...
CVE-2023-33307MEDIUM6.5A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 ...
CVE-2023-33306MEDIUM6.5A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 a...
CVE-2023-2831MEDIUM6.5Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Servi...
CVE-2023-2797MEDIUM6.5Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting ...
CVE-2023-2793MEDIUM6.5Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an at...
CVE-2023-2792MEDIUM6.5Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a sp...
CVE-2023-2785MEDIUM4.3Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to c...
CVE-2023-2791MEDIUM4.3When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated...
CVE-2023-2788MEDIUM6.5Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm...
CVE-2023-2787MEDIUM6.5Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary po...
CVE-2023-2786MEDIUM4.3Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post...
CVE-2023-2784MEDIUM6.5Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowin...
CVE-2023-2783MEDIUM4.3Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to...
CVE-2023-26541MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions.
CVE-2023-26013MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 vers...
CVE-2023-25963MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now