2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1095MEDIUM5.5In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction o...
CVE-2023-22999MEDIUM5.5In the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev retur...
CVE-2023-22998MEDIUM5.5In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table r...
CVE-2023-22997MEDIUM5.5In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expect...
CVE-2023-22996MEDIUM5.5In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference aft...
CVE-2023-27371MEDIUM5.9GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data b...
CVE-2023-1065MEDIUM5.3This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, whi...
CVE-2023-25431MEDIUM4.8An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/as...
CVE-2023-1018MEDIUM5.5An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 co...
CVE-2023-27295MEDIUM5.4Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can e...
CVE-2023-27294MEDIUM5.4Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted...
CVE-2023-27293MEDIUM6.1Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javas...
CVE-2023-27292MEDIUM5.4An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa...
CVE-2023-20857MEDIUM6.8VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted ...
CVE-2023-25807MEDIUM5.4DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved ...
CVE-2023-23983MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to th...
CVE-2023-23865MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 lea...
CVE-2023-23992MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.
CVE-2023-1080MEDIUM6.1The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in version...
CVE-2023-1028MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3...
CVE-2023-1027MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check ...
CVE-2023-1026MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t...
CVE-2023-1024MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check ...
CVE-2023-1023MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability ch...
CVE-2023-1022MEDIUM4.3The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now