2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-25781MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin ...
CVE-2023-2903MEDIUM6.5A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an u...
CVE-2023-31147MEDIUM6.5c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to g...
CVE-2023-31130MEDIUM6.4c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 ad...
CVE-2023-2902MEDIUM6.5A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by th...
CVE-2023-2901MEDIUM6.5A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by...
CVE-2023-2804MEDIUM6.5A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrge...
CVE-2023-2255MEDIUM5.3Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a docum...
CVE-2023-25439MEDIUM6.1Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr...
CVE-2023-26215MEDIUM6.5The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with lo...
CVE-2023-30851MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users...
CVE-2023-30615MEDIUM5.4Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations....
CVE-2023-33751MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H...
CVE-2023-33750MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H...
CVE-2023-32694MEDIUM5.4Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing ...
CVE-2023-33356MEDIUM5.4IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-22504MEDIUM6.5Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not wri...
CVE-2023-0459MEDIUM5.5Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to b...
CVE-2023-28370MEDIUM6.1Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a...
CVE-2023-2886MEDIUM4.3Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipu...
CVE-2023-2881MEDIUM4.9Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
CVE-2023-1158MEDIUM4.3 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard...
CVE-2023-33829MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute...
CVE-2023-33800MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allow...
CVE-2023-33799MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now