2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3286MEDIUM6.5A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in th...
CVE-2023-51778MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen...
CVE-2023-51777MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue sc...
CVE-2023-41928MEDIUM5.3The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.
CVE-2023-41927MEDIUM5.3The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing...
CVE-2023-41922MEDIUM5.4A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation,...
CVE-2023-50964MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-50953MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2023-50952MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authentica...
CVE-2023-50954MEDIUM5.3IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further at...
CVE-2023-4017MEDIUM6.1The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and '...
CVE-2023-47803MEDIUM5.3A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the...
CVE-2023-38370MEDIUM6.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the ne...
CVE-2023-38368MEDIUM5.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do ...
CVE-2023-42014MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnera...
CVE-2023-42011MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI ...
CVE-2023-30430MEDIUM5.5IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace l...
CVE-2023-7270MEDIUM5.3An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision...
CVE-2023-26877MEDIUM6.3File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .p...
CVE-2023-37541MEDIUM4.3HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai...
CVE-2023-45195MEDIUM5.3Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote...
CVE-2023-49793MEDIUM6.5CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Z...
CVE-2023-39517MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected ...
CVE-2023-38506MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasti...
CVE-2023-37898MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an un...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now