2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-44396MEDIUM5.4iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.1...
CVE-2023-43790MEDIUM5.4iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fie...
CVE-2023-38511MEDIUM4.3iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure...
CVE-2023-52144MEDIUM5.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Ma...
CVE-2023-7201MEDIUM6.5The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high ...
CVE-2023-6067MEDIUM5.4The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes ...
CVE-2023-6494MEDIUM4.4The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2023-52211MEDIUM5.3Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0...
CVE-2023-51499MEDIUM4.3Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipp...
CVE-2023-47714MEDIUM5.4IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scri...
CVE-2023-44856MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-44855MEDIUM6.5Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrar...
CVE-2023-44854MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-44853MEDIUM4.8\An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a cr...
CVE-2023-50307MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc...
CVE-2023-45186MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc...
CVE-2023-6678MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 1...
CVE-2023-6489MEDIUM6.5A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 ...
CVE-2023-48865MEDIUM6.5An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter ...
CVE-2023-32295MEDIUM6.3Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a ...
CVE-2023-32228MEDIUM4.6A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant...
CVE-2023-6257MEDIUM4.3The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users a...
CVE-2023-51141MEDIUM6.5An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentic...
CVE-2023-27607MEDIUM5.4Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Reward...
CVE-2023-6385MEDIUM4.3The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now