2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-26268MEDIUM5.3Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environm...
CVE-2023-31434MEDIUM5.4The parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in e...
CVE-2023-30943MEDIUM5.3The vulnerability was found Moodle which exists because the application allows a user to control path of the older to cr...
CVE-2023-29918MEDIUM5.4RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
CVE-2023-29868MEDIUM6.5Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and custom...
CVE-2023-29867MEDIUM6.5Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information a...
CVE-2023-2477MEDIUM6.1A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability i...
CVE-2023-2476MEDIUM5.4A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown...
CVE-2023-2445MEDIUM4.9Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers ...
CVE-2023-2475MEDIUM5.4A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown...
CVE-2023-2474MEDIUM4.3A vulnerability has been found in Rebuild 3.2 and classified as problematic. This vulnerability affects unknown code. Th...
CVE-2023-2473MEDIUM4.3A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects th...
CVE-2023-29772MEDIUM5.2A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC5...
CVE-2023-23723MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions...
CVE-2023-31207MEDIUM5.5Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause...
CVE-2023-2000MEDIUM5.4Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2023-1911MEDIUM4.3The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are alrea...
CVE-2023-1861MEDIUM5.4The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back...
CVE-2023-1805MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter ...
CVE-2023-1804MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter ...
CVE-2023-1614MEDIUM4.8The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could al...
CVE-2023-1554MEDIUM4.8The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which coul...
CVE-2023-1546MEDIUM6.1The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leadi...
CVE-2023-1525MEDIUM4.8The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-1125MEDIUM6.5The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user maki...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now