2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-23024MEDIUM6.1Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index...
CVE-2023-23015MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php.
CVE-2023-23014MEDIUM6.1Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr...
CVE-2023-23012MEDIUM6.1Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary co...
CVE-2023-23010MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c...
CVE-2023-22458MEDIUM5.5Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm...
CVE-2023-22912MEDIUM5.3An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Check...
CVE-2023-22910MEDIUM5.4An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There...
CVE-2023-20058MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate...
CVE-2023-20057MEDIUM5.3A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could ...
CVE-2023-20047MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi...
CVE-2023-20043MEDIUM6.7A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ...
CVE-2023-20040MEDIUM5.5A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote...
CVE-2023-20037MEDIUM5.4A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cro...
CVE-2023-20019MEDIUM6.1A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWork...
CVE-2023-20018MEDIUM6.5A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut...
CVE-2023-20002MEDIUM4.4A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass acce...
CVE-2023-22373MEDIUM5.4Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated att...
CVE-2023-22334MEDIUM5.3Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and ea...
CVE-2023-0410MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
CVE-2023-22745MEDIUM6.4tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 ...
CVE-2023-0406MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0404MEDIUM5.4The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev...
CVE-2023-0403MEDIUM5.4The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4....
CVE-2023-0402MEDIUM5.4The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now