2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0063MEDIUM5.4The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes b...
CVE-2023-1189MEDIUM5.5A vulnerability was found in WiseCleaner Wise Folder Hider 4.4.3.202. It has been declared as problematic. Affected by t...
CVE-2023-1188MEDIUM5.5A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affecte...
CVE-2023-1187MEDIUM5.5A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affec...
CVE-2023-1186MEDIUM5.5A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulner...
CVE-2023-22858MEDIUM5.3An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files ...
CVE-2023-22857MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in...
CVE-2023-22856MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in...
CVE-2023-26108MEDIUM5.3Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Ex...
CVE-2023-25077MEDIUM5.4Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p...
CVE-2023-22838MEDIUM5.4Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUB...
CVE-2023-22438MEDIUM5.4Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 ...
CVE-2023-22432MEDIUM6.1Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec...
CVE-2023-27641MEDIUM6.1The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS...
CVE-2023-26510MEDIUM5.7Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsiste...
CVE-2023-0734MEDIUM5.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
CVE-2023-1181MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.
CVE-2023-1180MEDIUM6.1A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as pr...
CVE-2023-1179MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory Sys...
CVE-2023-1175MEDIUM6.6Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
CVE-2023-26481MEDIUM6.5authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created...
CVE-2023-25819MEDIUM5.3Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T...
CVE-2023-26487MEDIUM6.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2023-26486MEDIUM6.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2023-26491MEDIUM6.1RSSHub is an open source and extensible RSS feed generator. When the URL parameters contain certain special characters, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now