2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-30571MEDIUM5.3Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write...
CVE-2023-27613MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versio...
CVE-2023-23699MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Reynolds Progress Bar plugin <= 2.2.1 vers...
CVE-2023-2808MEDIUM5.3Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlin...
CVE-2023-2954MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
CVE-2023-24605MEDIUM4.2OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading con...
CVE-2023-24604MEDIUM4.3OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing...
CVE-2023-24603MEDIUM6.5OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a craft...
CVE-2023-24602MEDIUM6.1OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
CVE-2023-24601MEDIUM6.1OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
CVE-2023-24600MEDIUM4.3OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via...
CVE-2023-24599MEDIUM4.3OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via co...
CVE-2023-24598MEDIUM4.3OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial di...
CVE-2023-24597MEDIUM5.3OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resour...
CVE-2023-28153MEDIUM6.4An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child ca...
CVE-2023-32762MEDIUM5.3An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorre...
CVE-2023-33332MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.
CVE-2023-33319MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plu...
CVE-2023-33311MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 v...
CVE-2023-33211MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin...
CVE-2023-32800MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <= 3.0.35 versions.
CVE-2023-28785MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
CVE-2023-33328MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 v...
CVE-2023-33326MEDIUM6.1Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.
CVE-2023-33309MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now