2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-27095MEDIUM6.5Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddU...
CVE-2023-27084MEDIUM5.3Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information...
CVE-2023-28487MEDIUM5.3Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2023-28486MEDIUM5.3Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-26951MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List modul...
CVE-2023-1421MEDIUM6.1A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker t...
CVE-2023-26912MEDIUM4.8Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb ...
CVE-2023-25680MEDIUM6.5IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Pro...
CVE-2023-25282MEDIUM6.5A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config....
CVE-2023-22876MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privilege...
CVE-2023-25804MEDIUM5.3Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a...
CVE-2023-1418MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System ...
CVE-2023-27102MEDIUM6.5Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segm...
CVE-2023-0322MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UN...
CVE-2023-25695MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow....
CVE-2023-27234MEDIUM6.5A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configura...
CVE-2023-27589MEDIUM6.5Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03...
CVE-2023-24923MEDIUM5.5Microsoft OneDrive for Android Information Disclosure Vulnerability
CVE-2023-24922MEDIUM6.5Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2023-24921MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24920MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24919MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24911MEDIUM4.3Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24906MEDIUM6.5Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24891MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now