2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0609MEDIUM4.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
CVE-2023-0608MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2023-0607MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
CVE-2023-23630MEDIUM6.1Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Exp...
CVE-2023-0606MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
CVE-2023-0593MEDIUM5.5A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attac...
CVE-2023-0592MEDIUM5.5A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attack...
CVE-2023-0591MEDIUM5.5 ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the...
CVE-2023-22389MEDIUM6.5 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configura...
CVE-2023-0097MEDIUM5.4The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of ...
CVE-2023-0074MEDIUM5.4The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before ...
CVE-2023-0071MEDIUM5.4The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputti...
CVE-2023-0033MEDIUM5.4The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could a...
CVE-2023-0581MEDIUM5.3The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side valid...
CVE-2023-22333MEDIUM6.1Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject a...
CVE-2023-22332MEDIUM6.5Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0...
CVE-2023-22324MEDIUM6.5SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attack...
CVE-2023-22322MEDIUM5.5Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and ea...
CVE-2023-24622MEDIUM5.3isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for ex...
CVE-2023-0572MEDIUM5.3Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-24065MEDIUM5.4NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billin...
CVE-2023-0566MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10....
CVE-2023-0565MEDIUM4.9Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0571MEDIUM5.4A vulnerability has been found in SourceCodester Canteen Management System 1.0 and classified as problematic. This vulne...
CVE-2023-0569MEDIUM6.5Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now