2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32189MEDIUM6.4Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
CVE-2023-7296MEDIUM6.4The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewe...
CVE-2023-7295MEDIUM6.1The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in ver...
CVE-2023-22649MEDIUM6.5A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Au...
CVE-2023-7294MEDIUM6.5The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t...
CVE-2023-7293MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a...
CVE-2023-7292MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal ...
CVE-2023-7290MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a...
CVE-2023-7289MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a...
CVE-2023-7288MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t...
CVE-2023-7287MEDIUM5.4The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati...
CVE-2023-7286MEDIUM6.5The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and ...
CVE-2023-31493MEDIUM6.6RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in langua...
CVE-2023-42133MEDIUM6.7PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav...
CVE-2023-45872MEDIUM6.5An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image wh...
CVE-2023-45361MEDIUM6.1An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40...
CVE-2023-45359MEDIUM6.5An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-to...
CVE-2023-26771MEDIUM6.5Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading...
CVE-2023-7273MEDIUM6.8Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has ...
CVE-2023-46175MEDIUM4.9IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which...
CVE-2023-52950MEDIUM5.3Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent befor...
CVE-2023-52949MEDIUM5.5Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for...
CVE-2023-52948MEDIUM5Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agen...
CVE-2023-51157MEDIUM5.4Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obt...
CVE-2023-26688MEDIUM5.4Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now