2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32958MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.
CVE-2023-33216MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodisc...
CVE-2023-2949MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2948MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2947MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2945MEDIUM5.4Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2944MEDIUM5.4Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2926MEDIUM6.5A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of th...
CVE-2023-2925MEDIUM5.4A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part...
CVE-2023-2922MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown fu...
CVE-2023-33184MEDIUM5.3Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the s...
CVE-2023-33195MEDIUM6.1Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This...
CVE-2023-33188MEDIUM5.5Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path va...
CVE-2023-32686MEDIUM5.4Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo...
CVE-2023-32325MEDIUM6.1PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cr...
CVE-2023-33199MEDIUM5.3Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects suppl...
CVE-2023-32319MEDIUM6.5Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints...
CVE-2023-32316MEDIUM4.3CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organiz...
CVE-2023-32311MEDIUM4.3CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organ...
CVE-2023-2898MEDIUM4.7There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw all...
CVE-2023-27311MEDIUM5.3NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architectu...
CVE-2023-33196MEDIUM5.4Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. T...
CVE-2023-33194MEDIUM4.8Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output i...
CVE-2023-33187MEDIUM6.5Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when...
CVE-2023-33185MEDIUM5.4Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS S...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now