2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-34222MEDIUM6.1In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
CVE-2023-34221MEDIUM5.4In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-34220MEDIUM5.4In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2023-34219MEDIUM4.3In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu...
CVE-2023-31548MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac...
CVE-2023-26842MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr...
CVE-2023-3009MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-33736MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web sc...
CVE-2023-3005MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management...
CVE-2023-2304MEDIUM5.4The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in ve...
CVE-2023-26131MEDIUM6.1All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/...
CVE-2023-2836MEDIUM4.8The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up t...
CVE-2023-1661MEDIUM5.4The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2023-2547MEDIUM5.4The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...
CVE-2023-2436MEDIUM4.4The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in v...
CVE-2023-2999MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-2998MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-23562MEDIUM4.3Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can upd...
CVE-2023-2612MEDIUM4.7Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when ...
CVE-2023-28350MEDIUM6.1An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized be...
CVE-2023-28345MEDIUM4.6An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the t...
CVE-2023-2952MEDIUM6.5XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injectio...
CVE-2023-34151MEDIUM5.5A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size...
CVE-2023-33962MEDIUM6.1JStachio is a type-safe Java Mustache templating engine. Prior to version 1.0.1, JStachio fails to escape single quotes...
CVE-2023-33961MEDIUM5.4Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with comment...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now