2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-33528MEDIUM6.1halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-25341MEDIUM6.5A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read...
CVE-2023-42956MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, mac...
CVE-2023-42936MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2,...
CVE-2023-42930MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Mon...
CVE-2023-42896MEDIUM5.5An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ve...
CVE-2023-42893MEDIUM5.5A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS...
CVE-2023-40390MEDIUM5.5A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2...
CVE-2023-45715MEDIUM4.3The console may experience a service interruption when processing file names with invalid characters.
CVE-2023-45706MEDIUM4An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit th...
CVE-2023-6371MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor...
CVE-2023-52234MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This i...
CVE-2023-52231MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This is...
CVE-2023-50374MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP –...
CVE-2023-36679MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a throug...
CVE-2023-47438MEDIUM6.5SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system inf...
CVE-2023-34020MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issu...
CVE-2023-50961MEDIUM5.4IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2023-25364MEDIUM6.1Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks.
CVE-2023-52228MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Kinchin Beds2...
CVE-2023-46049MEDIUM5.3LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhap...
CVE-2023-46048MEDIUM6.2Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it sho...
CVE-2023-46046MEDIUM5.5An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is di...
CVE-2023-45935MEDIUM4.2Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtom...
CVE-2023-45922MEDIUM4.3glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute()...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now