2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-22869MEDIUM5.5IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a loca...
CVE-2023-49275MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference...
CVE-2023-6897MEDIUM4.3The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an...
CVE-2023-6892MEDIUM5.4The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_p...
CVE-2023-50885MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator...
CVE-2023-49768MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Dre...
CVE-2023-3675MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web...
CVE-2023-41864MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF...
CVE-2023-4509MEDIUM4.3It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
CVE-2023-5407MEDIUM5.9Controller denial of service due to improper handling of a specially crafted message received by the controller. See Ho...
CVE-2023-5406MEDIUM5.9Server communication with a controller can lead to remote code execution using a specially crafted message from the cont...
CVE-2023-5405MEDIUM5.9Server information leak for the CDA Server process memory can occur when an error is generated in response to a speciall...
CVE-2023-5398MEDIUM5.9Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. Se...
CVE-2023-52645MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd ...
CVE-2023-6805MEDIUM6.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-52644MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct queue in DMA Tx path w...
CVE-2023-52643MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iio: core: fix memleak in iio_device_register_sysfs...
CVE-2023-25043MEDIUM4.3Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from ...
CVE-2023-45000MEDIUM5.3Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n...
CVE-2023-40000MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...
CVE-2023-45503MEDIUM5.3SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denia...
CVE-2023-47626MEDIUM6.1iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible...
CVE-2023-47622MEDIUM6.1iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is...
CVE-2023-47123MEDIUM5.4iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an...
CVE-2023-45808MEDIUM5.4iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now