2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-31285MEDIUM6.1An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some sp...
CVE-2023-22901MEDIUM4.9ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit...
CVE-2023-25292MEDIUM6.1Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated pr...
CVE-2023-1786MEDIUM5.5Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to f...
CVE-2023-30843MEDIUM6.5Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access t...
CVE-2023-29443MEDIUM4.9Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and...
CVE-2023-29442MEDIUM6.1Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
CVE-2023-29836MEDIUM6.1Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attack...
CVE-2023-31250MEDIUM6.5The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gain...
CVE-2023-30841MEDIUM5.5Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an...
CVE-2023-26930MEDIUM5.5Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc...
CVE-2023-0458MEDIUM4.7A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument...
CVE-2023-30212MEDIUM6.1OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
CVE-2023-2307MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
CVE-2023-30210MEDIUM6.1OURPHP <= 7.2.0 is vulnerable to Cross Site Scripting (XSS) via ourphp_tz.php.
CVE-2023-22729MEDIUM6.1Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr...
CVE-2023-30267MEDIUM6.1CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php.
CVE-2023-30265MEDIUM6.5CLTPHP <=6.0 is vulnerable to Directory Traversal.
CVE-2023-22728MEDIUM4.3Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr...
CVE-2023-2294MEDIUM6.1A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file...
CVE-2023-30111MEDIUM6.1Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-30106MEDIUM6.1Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.
CVE-2023-26560MEDIUM6.5Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports...
CVE-2023-31223MEDIUM5.4Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
CVE-2023-20870MEDIUM6VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing h...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now