2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-24625MEDIUM6.5Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object ...
CVE-2023-27242MEDIUM5.4SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the ...
CVE-2023-1616MEDIUM5.4A vulnerability was found in XiaoBingBy TeaCMS up to 2.0.2. It has been classified as problematic. Affected is an unknow...
CVE-2023-28818MEDIUM5.3An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included uns...
CVE-2023-28443MEDIUM5.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_...
CVE-2023-28442MEDIUM5.3GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Pri...
CVE-2023-28336MEDIUM4.3Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not...
CVE-2023-28334MEDIUM4.3Authenticated users were able to enumerate other users' names via the learning plans page.
CVE-2023-28332MEDIUM6.1If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presen...
CVE-2023-28331MEDIUM6.1Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVE-2023-28330MEDIUM6.5Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only...
CVE-2023-20861MEDIUM6.5In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versio...
CVE-2023-20859MEDIUM5.5In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is v...
CVE-2023-1613MEDIUM6.1A vulnerability has been found in Rebuild up to 3.2.3 and classified as problematic. This vulnerability affects unknown ...
CVE-2023-1402MEDIUM4.3The course participation report required additional checks to prevent roles being displayed which the user did not have ...
CVE-2023-1249MEDIUM5.5A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the sy...
CVE-2023-0590MEDIUM4.7A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This fl...
CVE-2023-0056MEDIUM6.5An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue c...
CVE-2023-26361MEDIUM4.9Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limit...
CVE-2023-1609MEDIUM5.4A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the...
CVE-2023-1544MEDIUM6.3A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver...
CVE-2023-1289MEDIUM5.5A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation ...
CVE-2023-26008MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay D'Souza Top 10 – Popular posts plugin for WordPre...
CVE-2023-25992MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 vers...
CVE-2023-25456MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Klaviyo, Inc. Klaviyo plugin <= 3.0.7 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now