2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32573MEDIUM6.5In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerE...
CVE-2023-30777MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced C...
CVE-2023-2615MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-2614MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-27919MEDIUM5.3Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a rem...
CVE-2023-27918MEDIUM6.1Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1....
CVE-2023-27888MEDIUM5.4Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject a...
CVE-2023-25070MEDIUM6.5Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the ...
CVE-2023-24586MEDIUM6.5Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may al...
CVE-2023-23901MEDIUM6.5Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and...
CVE-2023-22361MEDIUM6.5Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote aut...
CVE-2023-32570MEDIUM5.9VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_d...
CVE-2023-2616MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-26126MEDIUM5.3All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the pat...
CVE-2023-25833MEDIUM5.4There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth...
CVE-2023-28318MEDIUM5.3A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory o...
CVE-2023-28317MEDIUM5.3A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing th...
CVE-2023-28126MEDIUM5.9An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain...
CVE-2023-28125MEDIUM5.9An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attack...
CVE-2023-30057MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attac...
CVE-2023-25831MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unau...
CVE-2023-2609MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
CVE-2023-29338MEDIUM6.6Visual Studio Code Spoofing Vulnerability
CVE-2023-29324MEDIUM6.5Windows MSHTML Platform Security Feature Bypass Vulnerability
CVE-2023-28290MEDIUM5.3Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now