2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-33943MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay ...
CVE-2023-33942MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal ...
CVE-2023-33941MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedire...
CVE-2023-33940MEDIUM5.4Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Lifera...
CVE-2023-33939MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Life...
CVE-2023-33938MEDIUM6.1Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 ...
CVE-2023-33937MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and ...
CVE-2023-2864MEDIUM6.1A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this iss...
CVE-2023-2863MEDIUM5.5A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affec...
CVE-2023-2862MEDIUM6.1A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown fu...
CVE-2023-2498MEDIUM5.4The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2023-28015MEDIUM5.3The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed log...
CVE-2023-31860MEDIUM5.4Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.
CVE-2023-31518MEDIUM5.5A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial o...
CVE-2023-1209MEDIUM5.4Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbi...
CVE-2023-33599MEDIUM6.1EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php.
CVE-2023-33359MEDIUM4.3Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function.
CVE-2023-31669MEDIUM5.5WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
CVE-2023-2844MEDIUM4.9Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1...
CVE-2023-30469MEDIUM6.1Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) al...
CVE-2023-28390MEDIUM6.8Privilege escalation vulnerability in SR-7100VN firmware Ver.1.38(N) and earlier and SR-7100VN #31 firmware Ver.1.21 and...
CVE-2023-28367MEDIUM5.4Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a re...
CVE-2023-27926MEDIUM5.4Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allo...
CVE-2023-27925MEDIUM5.4Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and ear...
CVE-2023-27923MEDIUM5.4Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now