2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-25621MEDIUM6.5Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n...
CVE-2023-26303MEDIUM5.5Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions ...
CVE-2023-26302MEDIUM5.5Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was all...
CVE-2023-22972MEDIUM5.4A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7...
CVE-2023-24811MEDIUM6.1Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is ...
CVE-2023-24810MEDIUM6.1Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL durin...
CVE-2023-25154MEDIUM6.1Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to ...
CVE-2023-0846MEDIUM6.1Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Hori...
CVE-2023-26214MEDIUM5.4The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cr...
CVE-2023-23039MEDIUM5.7An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-...
CVE-2023-0949MEDIUM4.8Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.
CVE-2023-24081MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attac...
CVE-2023-25811MEDIUM5.4Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a pers...
CVE-2023-25810MEDIUM5.4Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persisten...
CVE-2023-0945MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affect...
CVE-2023-0942MEDIUM6.1The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ paramet...
CVE-2023-23009MEDIUM6.5Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS pa...
CVE-2023-22984MEDIUM6.1A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administra...
CVE-2023-0934MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5.
CVE-2023-25928MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-0936MEDIUM6.5A vulnerability was found in TP-Link Archer C50 V2_160801. It has been rated as problematic. Affected by this issue is s...
CVE-2023-26267MEDIUM6.5php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML...
CVE-2023-0559MEDIUM5.4The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes ...
CVE-2023-0541MEDIUM5.4The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before...
CVE-2023-0540MEDIUM5.4The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now