2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-52555MEDIUM6.1In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
CVE-2023-50312MEDIUM6.5IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbo...
CVE-2023-38366MEDIUM5.3IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse director...
CVE-2023-50324MEDIUM5.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an a...
CVE-2023-50305MEDIUM5.1IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by defaul...
CVE-2023-28949MEDIUM6.5IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an a...
CVE-2023-28525MEDIUM4.8IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2023-52485MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a comman...
CVE-2023-52484MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Fix soft lockup triggered by arm...
CVE-2023-52481MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivil...
CVE-2023-52478MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver U...
CVE-2023-52477MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized B...
CVE-2023-52476MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found t...
CVE-2023-50905MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ...
CVE-2023-1841MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Acc...
CVE-2023-51802MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execu...
CVE-2023-51800MEDIUM5.4Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbi...
CVE-2023-38367MEDIUM6.5IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19...
CVE-2023-27545MEDIUM5.5IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be...
CVE-2023-7207MEDIUM4.9Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches whic...
CVE-2023-7108MEDIUM6.1A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknow...
CVE-2023-6923MEDIUM6.1The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2023-6806MEDIUM5.4The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields i...
CVE-2023-6565MEDIUM5.9The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2023-6247MEDIUM6.5The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which woul...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now