2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-25730MEDIUM5.4A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser in...
CVE-2023-25728MEDIUM6.5The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted ...
CVE-2023-23604MEDIUM6.5A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromS...
CVE-2023-23603MEDIUM6.5Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` w...
CVE-2023-23602MEDIUM6.5A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src head...
CVE-2023-23601MEDIUM6.5Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to webs...
CVE-2023-23600MEDIUM6.5Per origin notification permissions were being stored in a way that didn't take into account what browsing context the p...
CVE-2023-23599MEDIUM6.5When copying a network request from the developer tools panel as a curl command the output was not being properly saniti...
CVE-2023-23598MEDIUM6.5Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing f...
CVE-2023-23597MEDIUM6.5A compromised web child process could disable web security opening restrictions, leading to a new child process being sp...
CVE-2023-1945MEDIUM6.5Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable cr...
CVE-2023-0616MEDIUM6.5If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d...
CVE-2023-0547MEDIUM6.5OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certif...
CVE-2023-0430MEDIUM6.5Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certific...
CVE-2023-3067MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.
CVE-2023-34094MEDIUM5.3ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 202...
CVE-2023-3060MEDIUM5.4A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as problematic. This vu...
CVE-2023-3058MEDIUM5.4A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unkn...
CVE-2023-3031MEDIUM4.9Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowi...
CVE-2023-33731MEDIUM6.1Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management co...
CVE-2023-33717MEDIUM5.5mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but...
CVE-2023-28469MEDIUM5.5An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2023-28705MEDIUM6.1Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A re...
CVE-2023-28700MEDIUM6.8OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area ...
CVE-2023-25780MEDIUM5.7It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now