2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1586MEDIUM4.7Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the resto...
CVE-2023-1585MEDIUM6.3Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quara...
CVE-2023-30614MEDIUM6.1Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is sus...
CVE-2023-30612MEDIUM4.9Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary op...
CVE-2023-30611MEDIUM5.3Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform....
CVE-2023-30610MEDIUM5.5aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` stru...
CVE-2023-22894MEDIUM4.9Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting ...
CVE-2023-29586MEDIUM5.5Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This ...
CVE-2023-29923MEDIUM5.3PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.
CVE-2023-27777MEDIUM5.4Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arb...
CVE-2023-29921MEDIUM5.3PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.
CVE-2023-27776MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows at...
CVE-2023-26599MEDIUM6.1XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client...
CVE-2023-25759MEDIUM5.4OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authen...
CVE-2023-0317MEDIUM4.9Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensi...
CVE-2023-2170MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v...
CVE-2023-2169MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v...
CVE-2023-2168MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in ver...
CVE-2023-25620MEDIUM6.5 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of servi...
CVE-2023-30605MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30558MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30557MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30556MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30555MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30554MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now