2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-24567MEDIUM6.5 Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user w...
CVE-2023-1117MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
CVE-2023-1116MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
CVE-2023-1115MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
CVE-2023-23984MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leadin...
CVE-2023-23974MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registrat...
CVE-2023-23973MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.
CVE-2023-1113MEDIUM4.8A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by ...
CVE-2023-22778MEDIUM4.8A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored...
CVE-2023-22777MEDIUM6.5An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful e...
CVE-2023-22776MEDIUM4.9An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t...
CVE-2023-22775MEDIUM6.5A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command lin...
CVE-2023-22774MEDIUM6.5Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of the...
CVE-2023-22773MEDIUM6.5Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of the...
CVE-2023-22772MEDIUM6.5An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitat...
CVE-2023-20085MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2023-20075MEDIUM6.7Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrar...
CVE-2023-20053MEDIUM6.1A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote at...
CVE-2023-20052MEDIUM5.3On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the D...
CVE-2023-0952MEDIUM6.5Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to ac...
CVE-2023-0567MEDIUM6.2In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some inval...
CVE-2023-1104MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2023-26608MEDIUM5.4SOLDR (System of Orchestration, Lifecycle control, Detection and Response) 1.1.0 allows stored XSS via the module editor...
CVE-2023-24045MEDIUM6.5In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specify...
CVE-2023-25575MEDIUM6.5API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now