2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0300MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository alfio-event/alf.io prior to 2.0-M4-2301.
CVE-2023-0298MEDIUM6.5Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
CVE-2023-23589MEDIUM6.5The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not th...
CVE-2023-22852MEDIUM6.5Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.
CVE-2023-22471MEDIUM4.3Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N...
CVE-2023-22470MEDIUM6.5Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2023-21599MEDIUM5.5Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that co...
CVE-2023-21598MEDIUM5.5Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could l...
CVE-2023-21592MEDIUM5.5Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that c...
CVE-2023-21591MEDIUM5.5Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that c...
CVE-2023-0295MEDIUM4.8The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters i...
CVE-2023-0294MEDIUM4.3The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t...
CVE-2023-0293MEDIUM4.3The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capab...
CVE-2023-22491MEDIUM5.4Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-tran...
CVE-2023-0289MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
CVE-2023-0221MEDIUM4.4Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrat...
CVE-2023-0287MEDIUM5.4A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some u...
CVE-2023-0105MEDIUM6.5A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correc...
CVE-2023-22414MEDIUM6.5A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Network...
CVE-2023-22410MEDIUM6.5A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Networks Junos OS on MX Series platfor...
CVE-2023-22409MEDIUM5.5An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authent...
CVE-2023-22407MEDIUM6.5An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolv...
CVE-2023-22406MEDIUM6.5A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos ...
CVE-2023-22405MEDIUM6.5An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet ...
CVE-2023-22404MEDIUM6.5An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now