2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-25134MEDIUM6.7McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee spe...
CVE-2023-25686MEDIUM5.5IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text ...
CVE-2023-27873MEDIUM6.5 IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using sp...
CVE-2023-25689MEDIUM5.3IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse d...
CVE-2023-25687MEDIUM4.3IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain ...
CVE-2023-27983MEDIUM5.3A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could...
CVE-2023-27979MEDIUM6.5A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r...
CVE-2023-27977MEDIUM5.3A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces...
CVE-2023-1154MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pacsrapor allows R...
CVE-2023-1542MEDIUM5.4Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1540MEDIUM5.3Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1539MEDIUM5.3Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1538MEDIUM5.3Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1536MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1535MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1527MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.
CVE-2023-28425MEDIUM5.5Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticat...
CVE-2023-0681MEDIUM6.1Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the abi...
CVE-2023-22288MEDIUM5.4HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticate...
CVE-2023-1517MEDIUM4.8Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-0937MEDIUM6.1The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter ...
CVE-2023-0911MEDIUM6.5The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to ...
CVE-2023-0890MEDIUM6.5The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be di...
CVE-2023-0876MEDIUM6.1The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to m...
CVE-2023-0370MEDIUM5.4The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now