2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-47715MEDIUM4.3IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to a...
CVE-2023-48903MEDIUM6.1Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers ...
CVE-2023-6500MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2023-49985MEDIUM6.5A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allo...
CVE-2023-49984MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 a...
CVE-2023-49983MEDIUM6.8A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allo...
CVE-2023-38825MEDIUM6.5SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive informatio...
CVE-2023-45177MEDIUM5.3IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within ...
CVE-2023-51445MEDIUM4.8GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A store...
CVE-2023-35888MEDIUM5.9IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failu...
CVE-2023-52229MEDIUM6.5Missing Authorization vulnerability in Save as PDF plugin by Pdfcrowd Word Replacer Pro.This issue affects Word Replacer...
CVE-2023-46841MEDIUM6.5Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow S...
CVE-2023-46840MEDIUM4.1Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when su...
CVE-2023-46839MEDIUM5.3PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate re...
CVE-2023-7246MEDIUM5.4The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow admi...
CVE-2023-50811MEDIUM6.5An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter rel...
CVE-2023-44090MEDIUM6.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on al...
CVE-2023-41793MEDIUM6.5: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing director...
CVE-2023-32260MEDIUM6.5Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management...
CVE-2023-32259MEDIUM6.5Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ ...
CVE-2023-50966MEDIUM5.3erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumptio...
CVE-2023-5388MEDIUM6.5NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow ...
CVE-2023-40277MEDIUM6.1An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discove...
CVE-2023-7236MEDIUM4.7The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug...
CVE-2023-7085MEDIUM5.4The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now