2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0414MEDIUM6.5Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture ...
CVE-2023-0413MEDIUM6.5Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ...
CVE-2023-0411MEDIUM6.5Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via ...
CVE-2023-0394MEDIUM5.5A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in ...
CVE-2023-0229MEDIUM6.3A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue t...
CVE-2023-0396MEDIUM6.8A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command r...
CVE-2023-22485MEDIUM5.3cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29...
CVE-2023-21719MEDIUM6.5Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-22630MEDIUM4.3IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
CVE-2023-23687MEDIUM5.4Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
CVE-2023-22721MEDIUM5.4Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
CVE-2023-0447MEDIUM4.3The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t...
CVE-2023-0446MEDIUM5.5The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in ...
CVE-2023-0440MEDIUM5.3Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.
CVE-2023-0438MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-24070MEDIUM6.1app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
CVE-2023-24058MEDIUM4.3Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId...
CVE-2023-24056MEDIUM5.5In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgcon...
CVE-2023-24055MEDIUM5.5KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,...
CVE-2023-24044MEDIUM6.1A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to ...
CVE-2023-22742MEDIUM5.9libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 ...
CVE-2023-24027MEDIUM6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2023-24026MEDIUM6.1In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
CVE-2023-23491MEDIUM6.1The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability...
CVE-2023-23144MEDIUM5.5Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now