2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-26116MEDIUM5.3Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angul...
CVE-2023-25000MEDIUM4.7HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-...
CVE-2023-0665MEDIUM6.5HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer met...
CVE-2023-0620MEDIUM6.7HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when config...
CVE-2023-22705MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions.
CVE-2023-27489MEDIUM5.4Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files up...
CVE-2023-25809MEDIUM6.3runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was f...
CVE-2023-27167MEDIUM6.5Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs...
CVE-2023-26292MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-26291MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-26290MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-1550MEDIUM5.5Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 ins...
CVE-2023-1704MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1703MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1702MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1701MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-26982MEDIUM5.4Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter un...
CVE-2023-1575MEDIUM4.8The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters...
CVE-2023-1663MEDIUM5.3Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthor...
CVE-2023-28158MEDIUM5.4Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploite...
CVE-2023-1690MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App ...
CVE-2023-1689MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnera...
CVE-2023-1688MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This af...
CVE-2023-1687MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected i...
CVE-2023-1686MEDIUM6.1A vulnerability was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. It has been rated as problematic. T...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now