2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2281MEDIUM4.3When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi...
CVE-2023-30417MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scr...
CVE-2023-26843MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr...
CVE-2023-26841MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password exc...
CVE-2023-26840MEDIUM5.3A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set...
CVE-2023-26839MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing ...
CVE-2023-26058MEDIUM6.5An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input va...
CVE-2023-26057MEDIUM6.5An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. In...
CVE-2023-25347MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web sc...
CVE-2023-25346MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web ...
CVE-2023-27619MEDIUM5.4Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 version...
CVE-2023-25710MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1....
CVE-2023-25490MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plug...
CVE-2023-25479MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versi...
CVE-2023-22665MEDIUM5.4There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. ...
CVE-2023-30414MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.
CVE-2023-30410MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /o...
CVE-2023-30408MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
CVE-2023-30406MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property...
CVE-2023-30627MEDIUM5.4jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to versi...
CVE-2023-2250MEDIUM6.7A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-...
CVE-2023-2019MEDIUM4.4A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from...
CVE-2023-29469MEDIUM6.5An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComp...
CVE-2023-28484MEDIUM6.5In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently...
CVE-2023-29530MEDIUM6.5Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now