2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-28600MEDIUM5.4Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to...
CVE-2023-34247MEDIUM4.1Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package version...
CVE-2023-33620MEDIUM5.9GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdro...
CVE-2023-31439MEDIUM5.3An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then...
CVE-2023-31438MEDIUM5.3An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that...
CVE-2023-31437MEDIUM5.3An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all exist...
CVE-2023-28599MEDIUM4.3Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their d...
CVE-2023-28598MEDIUM6.5Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malic...
CVE-2023-33621MEDIUM5.9GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server ...
CVE-2023-27624MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 ver...
CVE-2023-25978MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nate Reist Protected Posts Logout Button plugin <= 1.4...
CVE-2023-28620MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cyberus Labs Cyberus Key plugin <= 1.0 versions.
CVE-2023-26538MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions.
CVE-2023-26528MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 ...
CVE-2023-25964MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46...
CVE-2023-23831MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rating-Widget Rating-Widget: Star Review System ...
CVE-2023-3218MEDIUM4.4Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
CVE-2023-32546MEDIUM4.4Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is e...
CVE-2023-31195MEDIUM5.3ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. Wh...
CVE-2023-29501MEDIUM4.8Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku coupon App for Android vers...
CVE-2023-29498MEDIUM5.5Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earli...
CVE-2023-33921MEDIUM6.8A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver...
CVE-2023-33920MEDIUM6.8A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver...
CVE-2023-33305MEDIUM6.5A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS versio...
CVE-2023-33122MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now