2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6725MEDIUM5.5An access-control flaw was found in the OpenStack Designate component where private configuration information including ...
CVE-2023-43490MEDIUM5.3Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a...
CVE-2023-39368MEDIUM6.5Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to pot...
CVE-2023-38575MEDIUM5.5Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized...
CVE-2023-35191MEDIUM6.8Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially ena...
CVE-2023-32633MEDIUM6.7Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated u...
CVE-2023-28746MEDIUM6.5Information exposure through microarchitectural state after transient execution from some register files for some Intel(...
CVE-2023-28389MEDIUM6.7Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica...
CVE-2023-22655MEDIUM6.1Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel...
CVE-2023-38536MEDIUM6.1HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site script...
CVE-2023-50726MEDIUM6.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows...
CVE-2023-36238MEDIUM6.5Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the in...
CVE-2023-7015MEDIUM6.1The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all ...
CVE-2023-6969MEDIUM4.3The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a...
CVE-2023-6957MEDIUM5.4The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2023-6954MEDIUM5.4The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)...
CVE-2023-6880MEDIUM5.4The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl...
CVE-2023-6809MEDIUM5.4The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortc...
CVE-2023-6785MEDIUM5.3The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a...
CVE-2023-52608MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for c...
CVE-2023-43043MEDIUM5.5IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user....
CVE-2023-38723MEDIUM6.4IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2023-28517MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerabilit...
CVE-2023-4839MEDIUM4.8The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and incl...
CVE-2023-43279MEDIUM6.5Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now