2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30531MEDIUM6.5Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configura...
CVE-2023-30530MEDIUM4.3Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global conf...
CVE-2023-30529MEDIUM4.3Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowi...
CVE-2023-30528MEDIUM6.5Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, i...
CVE-2023-30527MEDIUM4.3Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file ...
CVE-2023-30526MEDIUM6.5A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission...
CVE-2023-30525HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to co...
CVE-2023-30524MEDIUM4.3Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration for...
CVE-2023-30523MEDIUM4.3Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on th...
CVE-2023-30522MEDIUM4.3A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to tr...
CVE-2023-30521MEDIUM5.3A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated at...
CVE-2023-30520MEDIUM5.4Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Qua...
CVE-2023-30519MEDIUM5.3A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger...
CVE-2023-30518MEDIUM4.3A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read...
CVE-2023-30517MEDIUM5.3Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostnam...
CVE-2023-30516MEDIUM6.5Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when...
CVE-2023-30515HIGH7.5Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) cre...
CVE-2023-30514HIGH7.5Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) cre...
CVE-2023-30513HIGH7.5Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentia...
CVE-2023-27216HIGH8.8An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the net...
CVE-2023-26852HIGH7.2An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute ...
CVE-2023-0006MEDIUM6.3A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to del...
CVE-2023-0005MEDIUM4.9A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext val...
CVE-2023-0004MEDIUM6.5A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to dele...
CVE-2023-29581MEDIUM5.5yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE:...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now