2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-49977MEDIUM5.4A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49976MEDIUM5.4A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49974MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49973MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49971MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-48644MEDIUM6.1An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feat...
CVE-2023-45290MEDIUM6.5When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, R...
CVE-2023-45289MEDIUM4.3When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http...
CVE-2023-26282MEDIUM4.2IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy...
CVE-2023-25681MEDIUM6.5LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authentic...
CVE-2023-45598MEDIUM5.3A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allow...
CVE-2023-45596MEDIUM5.3A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web applic...
CVE-2023-45594MEDIUM6.8A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a ...
CVE-2023-45593MEDIUM6.8A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling...
CVE-2023-49969MEDIUM4.3Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup...
CVE-2023-41829MEDIUM5An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious,...
CVE-2023-41827MEDIUM5.1An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, loca...
CVE-2023-38360MEDIUM6.1IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2023-5451MEDIUM6.1Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Ma...
CVE-2023-38362MEDIUM5.3IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTT...
CVE-2023-33090MEDIUM5.5Transient DOS while processing channel information for speaker protection v2 module in ADSP.
CVE-2023-33078MEDIUM5.5Information Disclosure while processing IOCTL request in FastRPC.
CVE-2023-4479MEDIUM5.4Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stor...
CVE-2023-49602MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2023-25176MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now