2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-45920MEDIUM4.2Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed beca...
CVE-2023-45919MEDIUM5.3Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there...
CVE-2023-45913MEDIUM6.2Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). ...
CVE-2023-40285MEDIUM6.5An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS is...
CVE-2023-39804MEDIUM6.2In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVE-2023-27630MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affect...
CVE-2023-25965MEDIUM5.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Up...
CVE-2023-52627MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device ...
CVE-2023-52625MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Refactor DMCUB enter/exit idle int...
CVE-2023-52623MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I recei...
CVE-2023-52622MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversiz...
CVE-2023-7251MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Su...
CVE-2023-49838MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme...
CVE-2023-33322MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design ...
CVE-2023-32237MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem...
CVE-2023-51416MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/...
CVE-2023-7232MEDIUM5.3The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive inf...
CVE-2023-48296MEDIUM4.3OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items...
CVE-2023-45824MEDIUM4.3OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages o...
CVE-2023-22699MEDIUM5.4Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: ...
CVE-2023-33923MEDIUM4.3Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Vi...
CVE-2023-30480MEDIUM4.3Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
CVE-2023-4063MEDIUM5.3Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET ...
CVE-2023-42954MEDIUM4.9A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websit...
CVE-2023-49837MEDIUM6.5Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a throu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now