2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0794MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0792MEDIUM5.4Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0791MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0787MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0786MEDIUM4.8Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0661MEDIUM6.5Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
CVE-2023-0780MEDIUM5.4Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
CVE-2023-23161MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e...
CVE-2023-24234MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventor...
CVE-2023-24233MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of ...
CVE-2023-24232MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inven...
CVE-2023-24231MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of In...
CVE-2023-24230MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows ...
CVE-2023-23286MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s...
CVE-2023-24690MEDIUM5.4ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/reg...
CVE-2023-24686MEDIUM4.8An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importi...
CVE-2023-24689MEDIUM4.3An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of...
CVE-2023-24688MEDIUM5.3An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registr...
CVE-2023-24687MEDIUM5.4Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Sett...
CVE-2023-24322MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta...
CVE-2023-22798MEDIUM6.1Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interc...
CVE-2023-22797MEDIUM6.1An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling red...
CVE-2023-21446MEDIUM5.5Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.0...
CVE-2023-21442MEDIUM5.5Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.0...
CVE-2023-21441MEDIUM5.5Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now