2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1752MEDIUM4.3The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associate...
CVE-2023-1751MEDIUM5.3The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the ...
CVE-2023-1749MEDIUM6.5The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a val...
CVE-2023-26974MEDIUM5.5Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000...
CVE-2023-27734MEDIUM5.5An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbol...
CVE-2023-26777MEDIUM6.1Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execu...
CVE-2023-26776MEDIUM6.1Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the ...
CVE-2023-26437MEDIUM5.3Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue af...
CVE-2023-29000MEDIUM6.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28999MEDIUM6.4Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app ...
CVE-2023-28998MEDIUM6.1The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28997MEDIUM6.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28848MEDIUM5.4user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in vers...
CVE-2023-23977MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin fo...
CVE-2023-23870MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8...
CVE-2023-23878MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAP...
CVE-2023-23821MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcin Pietrzak Interactive Polish Map plugin <= 1.2 v...
CVE-2023-23686MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.2...
CVE-2023-23685MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plug...
CVE-2023-25942MEDIUM6.5 Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious netw...
CVE-2023-1768MEDIUM5.3Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk...
CVE-2023-0922MEDIUM5.9The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset pass...
CVE-2023-0614MEDIUM6.5The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuf...
CVE-2023-0225MEDIUM4.3A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged use...
CVE-2023-26916MEDIUM5.3libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now