2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2671MEDIUM6.1A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as problematic. Thi...
CVE-2023-2674MEDIUM4.3Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-28936MEDIUM5.3Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeet...
CVE-2023-2667MEDIUM6.1A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as problematic. Af...
CVE-2023-28520MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ...
CVE-2023-29808MEDIUM6.1Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.
CVE-2023-29286MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability ...
CVE-2023-29279MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le...
CVE-2023-29277MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le...
CVE-2023-28361MEDIUM6.5A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to acc...
CVE-2023-28360MEDIUM4.3An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user...
CVE-2023-28359MEDIUM5.3A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be e...
CVE-2023-28358MEDIUM6.1A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allow...
CVE-2023-28357MEDIUM4.3A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking...
CVE-2023-28325MEDIUM6.5An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param...
CVE-2023-2664MEDIUM5.5 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflo...
CVE-2023-2663MEDIUM5.5 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. ...
CVE-2023-2662MEDIUM5.5In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
CVE-2023-29791MEDIUM6.1kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
CVE-2023-32082MEDIUM4.3etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the Leas...
CVE-2023-29195MEDIUM4.3Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16...
CVE-2023-27870MEDIUM5.9 IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a downl...
CVE-2023-27554MEDIUM6.3 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces...
CVE-2023-30394MEDIUM6.1The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this is...
CVE-2023-29029MEDIUM5.9 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now