2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0109MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability all...
CVE-2023-4134MEDIUM5.5A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device...
CVE-2023-34049MEDIUM6.7The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force ...
CVE-2023-38920MEDIUM4.8Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary co...
CVE-2023-44255MEDIUM4.1An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnal...
CVE-2023-1932MEDIUM6.1A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators....
CVE-2023-29122MEDIUM6.7Under certain conditions, access to service libraries is granted to account they should not have access to.
CVE-2023-29116MEDIUM4.3Under certain conditions, through a request directed to the Waybox Enel X web management application, information like W...
CVE-2023-29115MEDIUM6.5In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service...
CVE-2023-29114MEDIUM5.7System logs could be accessed through web management application due to a lack of access control. An attacker can obta...
CVE-2023-52920MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from st...
CVE-2023-34445MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible f...
CVE-2023-34444MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possib...
CVE-2023-34443MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (X...
CVE-2023-52045MEDIUM6.1Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vuln...
CVE-2023-5816MEDIUM4.9The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu...
CVE-2023-26248MEDIUM5.3The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information fo...
CVE-2023-50355MEDIUM5.3HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t...
CVE-2023-52919MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in ...
CVE-2023-52918MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() retu...
CVE-2023-6243MEDIUM4.3The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge...
CVE-2023-6058MEDIUM6.8A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the pr...
CVE-2023-49567MEDIUM6.8A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product inc...
CVE-2023-39593MEDIUM5.6Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary comma...
CVE-2023-32266MEDIUM5.3Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now