2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7282MEDIUM4.3Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc...
CVE-2023-7281MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor...
CVE-2023-46948MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attac...
CVE-2023-41611MEDIUM6.5Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
CVE-2023-43753MEDIUM6.8Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enabl...
CVE-2023-23904MEDIUM6.9NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially en...
CVE-2023-22351MEDIUM6.9Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable esca...
CVE-2023-3410MEDIUM5.4The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up...
CVE-2023-44254MEDIUM6.5An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7....
CVE-2023-49069MEDIUM6.9A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech...
CVE-2023-30755MEDIUM5.9A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-2919MEDIUM4.3The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. ...
CVE-2023-50883MEDIUM6.1ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and theref...
CVE-2023-39333MEDIUM5.3Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be ...
CVE-2023-30582MEDIUM5.3A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the...
CVE-2023-51368MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2023-51366MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2023-50366MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2023-52915MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af...
CVE-2023-51712MEDIUM4.7An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem ...
CVE-2023-7279MEDIUM5.9A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This...
CVE-2023-7256MEDIUM4.4In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls ...
CVE-2023-49582MEDIUM5.5Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to name...
CVE-2023-48957MEDIUM5.3PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and ...
CVE-2023-6987MEDIUM6.1The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now