2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1237MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-22847MEDIUM4.3Information disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialize...
CVE-2023-1212MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-0330MEDIUM6A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to m...
CVE-2023-24737MEDIUM6.1PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad...
CVE-2023-24735MEDIUM6.1PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil...
CVE-2023-24733MEDIUM6.1PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad...
CVE-2023-26600MEDIUM6.5ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and ...
CVE-2023-27472MEDIUM6.1 quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in ent...
CVE-2023-26054MEDIUM6.5BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I...
CVE-2023-25169MEDIUM5.3discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a ...
CVE-2023-22481MEDIUM5.5FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `...
CVE-2023-27474MEDIUM5.4Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed re...
CVE-2023-1200MEDIUM5.4A vulnerability was found in ehuacui bbs. It has been declared as problematic. This vulnerability affects unknown code. ...
CVE-2023-1197MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.
CVE-2023-0377MEDIUM5.4The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options befor...
CVE-2023-0328MEDIUM4.3The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only...
CVE-2023-0212MEDIUM5.4The Advanced Recent Posts WordPress plugin through 0.6.14 does not validate and escape some of its shortcode attributes ...
CVE-2023-0165MEDIUM5.4The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before ou...
CVE-2023-0078MEDIUM5.4The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which ...
CVE-2023-0076MEDIUM5.4The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0069MEDIUM5.4The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes befo...
CVE-2023-0068MEDIUM5.4The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of it...
CVE-2023-0065MEDIUM5.4The i2 Pros & Cons WordPress plugin through 1.3.1 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0064MEDIUM5.4The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its sh...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now