2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29437MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory pl...
CVE-2023-36631HIGH7.8Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged us...
CVE-2023-29435MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Zwaply Cryptocurrency All-in-One plugin <= 3.0.1...
CVE-2023-3398HIGH7.5Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
CVE-2023-29436MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versio...
CVE-2023-29434MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin ...
CVE-2023-29430MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.
CVE-2023-29427MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia ...
CVE-2023-29424MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling pl...
CVE-2023-29423MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / R...
CVE-2023-22359MEDIUM4.3User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
CVE-2023-1620MEDIUM4.9Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de...
CVE-2023-1619MEDIUM4.9Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de...
CVE-2023-1150HIGH7.5Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS...
CVE-2023-29093MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Con...
CVE-2023-28992MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP Coupon Affiliates – WooCommerce Af...
CVE-2023-28991MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date ti...
CVE-2023-28988MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, ...
CVE-2023-36675MEDIUM6.1An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. Bloc...
CVE-2023-36662MEDIUM5.4The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affe...
CVE-2023-36666MEDIUM6.1INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, pag...
CVE-2023-36664HIGH7.8Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pi...
CVE-2023-36661HIGH7.5Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyIn...
CVE-2023-36660CRITICAL9.8The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
CVE-2023-36663HIGH8.8it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the so...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now