2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0642MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
CVE-2023-0639MEDIUM6.1A vulnerability was found in TRENDnet TEW-652BRP 3.04b01 and classified as problematic. This issue affects some unknown ...
CVE-2023-0637MEDIUM6.5A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown pa...
CVE-2023-25015MEDIUM6.5Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF.
CVE-2023-25012MEDIUM4.6The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB dev...
CVE-2023-0599MEDIUM4.8Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack o...
CVE-2023-23751MEDIUM4.3An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_a...
CVE-2023-23750MEDIUM6.3An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handlin...
CVE-2023-23078MEDIUM6.1Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing th...
CVE-2023-23077MEDIUM6.1Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a ne...
CVE-2023-23075MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets W...
CVE-2023-23074MEDIUM6.1Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language c...
CVE-2023-23073MEDIUM6.1Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
CVE-2023-0619MEDIUM6.5The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability che...
CVE-2023-22418MEDIUM6.1On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versio...
CVE-2023-22326MEDIUM4.9In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a...
CVE-2023-22302MEDIUM5.9In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is ...
CVE-2023-22283MEDIUM6.5On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Win...
CVE-2023-23136MEDIUM6.5lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.
CVE-2023-23130MEDIUM5.9Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext...
CVE-2023-23128MEDIUM6.1Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that...
CVE-2023-23127MEDIUM5.3In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NO...
CVE-2023-23126MEDIUM6.1Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users...
CVE-2023-22573MEDIUM5.5Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloud...
CVE-2023-0610MEDIUM4.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now