2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-26483MEDIUM5.3gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication suppo...
CVE-2023-26047MEDIUM6.1teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-w...
CVE-2023-1170MEDIUM6.6Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
CVE-2023-26488MEDIUM6.5OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for m...
CVE-2023-23927MEDIUM5.4Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an...
CVE-2023-23313MEDIUM6.1Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi scrip...
CVE-2023-0968MEDIUM6.1The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and ...
CVE-2023-20104MEDIUM6.1A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attac...
CVE-2023-20069MEDIUM5.4A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo...
CVE-2023-20062MEDIUM4.3Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s...
CVE-2023-20061MEDIUM6.5Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s...
CVE-2023-1163MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as c...
CVE-2023-0578MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T...
CVE-2023-0577MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T...
CVE-2023-1160MEDIUM5.5Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
CVE-2023-26473MEDIUM6.5XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary ...
CVE-2023-26056MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with t...
CVE-2023-26052MEDIUM5.3Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python excep...
CVE-2023-26051MEDIUM4.3Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python excep...
CVE-2023-1157MEDIUM5.5A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_par...
CVE-2023-1156MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0...
CVE-2023-0084MEDIUM6.1The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text ar...
CVE-2023-26480MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a store...
CVE-2023-26479MEDIUM6.5XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed conte...
CVE-2023-1155MEDIUM5.4The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_ic...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now