2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1090MEDIUM4.8The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allo...
CVE-2023-1021MEDIUM4.8The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could al...
CVE-2023-0891MEDIUM5.4The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-2247MEDIUM5.3In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
CVE-2023-30639MEDIUM5.4Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated maliciou...
CVE-2023-29681MEDIUM5.7Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker ...
CVE-2023-29680MEDIUM5.7Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attac...
CVE-2023-27108MEDIUM5.3An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns t...
CVE-2023-26987MEDIUM6.5An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via craf...
CVE-2023-22924MEDIUM4.9A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot...
CVE-2023-22923MEDIUM6.5A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could all...
CVE-2023-22503MEDIUM5.3Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of a...
CVE-2023-29643MEDIUM5.4Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post fu...
CVE-2023-29641MEDIUM6.1Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script ...
CVE-2023-29639MEDIUM5.4Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-29638MEDIUM5.4Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, ...
CVE-2023-29637MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-29636MEDIUM5.4Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-28092MEDIUM6.8A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could resul...
CVE-2023-2428MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
CVE-2023-2426MEDIUM5.5Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
CVE-2023-2425MEDIUM4.8A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been classified as problematic...
CVE-2023-30792MEDIUM6.1Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link cl...
CVE-2023-2421MEDIUM6.1A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function o...
CVE-2023-2418MEDIUM5.9A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now