2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-23949MEDIUM5.4An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
CVE-2023-23613MEDIUM6.5OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implem...
CVE-2023-23611MEDIUM5.4LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provid...
CVE-2023-23610MEDIUM6.5GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper ...
CVE-2023-23608MEDIUM4.3Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is pas...
CVE-2023-23151MEDIUM6.5bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_co...
CVE-2023-22971MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, ...
CVE-2023-22739MEDIUM6.5Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and...
CVE-2023-22725MEDIUM4.8GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cro...
CVE-2023-22724MEDIUM4.8GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting vi...
CVE-2023-22722MEDIUM6.1GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-...
CVE-2023-22468MEDIUM5.4Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an...
CVE-2023-20924MEDIUM6.8In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo...
CVE-2023-20923MEDIUM5.5In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to...
CVE-2023-20922MEDIUM5.5In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea...
CVE-2023-20908MEDIUM5.5In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could...
CVE-2023-0513MEDIUM5.4A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability a...
CVE-2023-0476MEDIUM6.5A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning i...
CVE-2023-0469MEDIUM5.5A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin...
CVE-2023-0468MEDIUM4.7A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Ker...
CVE-2023-0452MEDIUM5.3Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configura...
CVE-2023-0448MEDIUM6.1The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resultin...
CVE-2023-0417MEDIUM6.5Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet...
CVE-2023-0416MEDIUM6.5GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or...
CVE-2023-0415MEDIUM6.5iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now