2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0062MEDIUM5.4The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes befo...
CVE-2023-24197MEDIUM6.1Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_orde...
CVE-2023-24195MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet...
CVE-2023-24194MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet...
CVE-2023-24192MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par...
CVE-2023-24191MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par...
CVE-2023-22849MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ...
CVE-2023-0678MEDIUM5.3Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0677MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0676MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVE-2023-0674MEDIUM6.5A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some un...
CVE-2023-23615MEDIUM5.3Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any us...
CVE-2023-23082MEDIUM4.6A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of serv...
CVE-2023-23940MEDIUM5.3OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a dec...
CVE-2023-23937MEDIUM5.4Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upl...
CVE-2023-23933MEDIUM4.3OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. There is an issue with the a...
CVE-2023-22975MEDIUM6.1A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM...
CVE-2023-25136MEDIUM6.5OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i...
CVE-2023-24613MEDIUM4.9The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb t...
CVE-2023-23636MEDIUM5.4In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal ...
CVE-2023-23635MEDIUM5.4In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to stea...
CVE-2023-23120MEDIUM5.9The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP65...
CVE-2023-23119MEDIUM5.9The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFibe...
CVE-2023-0650MEDIUM5.4A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processi...
CVE-2023-0643MEDIUM6.1Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now