2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30531 | MEDIUM | 6.5 | 0.4% | Apr 12, 2023 | Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configura... |
| CVE-2023-30530 | MEDIUM | 4.3 | 0.3% | Apr 12, 2023 | Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global conf... |
| CVE-2023-30529 | MEDIUM | 4.3 | 0.3% | Apr 12, 2023 | Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowi... |
| CVE-2023-30528 | MEDIUM | 6.5 | 0.4% | Apr 12, 2023 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, i... |
| CVE-2023-30527 | MEDIUM | 4.3 | 0.3% | Apr 12, 2023 | Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file ... |
| CVE-2023-30526 | MEDIUM | 6.5 | 0.5% | Apr 12, 2023 | A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission... |
| CVE-2023-30525 | HIGH | 8.8 | 0.8% | Apr 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to co... |
| CVE-2023-30524 | MEDIUM | 4.3 | 0.4% | Apr 12, 2023 | Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration for... |
| CVE-2023-30523 | MEDIUM | 4.3 | 0.3% | Apr 12, 2023 | Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on th... |
| CVE-2023-30522 | MEDIUM | 4.3 | 0.4% | Apr 12, 2023 | A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to tr... |
| CVE-2023-30521 | MEDIUM | 5.3 | 0.5% | Apr 12, 2023 | A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated at... |
| CVE-2023-30520 | MEDIUM | 5.4 | 0.5% | Apr 12, 2023 | Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Qua... |
| CVE-2023-30519 | MEDIUM | 5.3 | 0.5% | Apr 12, 2023 | A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger... |
| CVE-2023-30518 | MEDIUM | 4.3 | 0.5% | Apr 12, 2023 | A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read... |
| CVE-2023-30517 | MEDIUM | 5.3 | 0.3% | Apr 12, 2023 | Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostnam... |
| CVE-2023-30516 | MEDIUM | 6.5 | 0.5% | Apr 12, 2023 | Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when... |
| CVE-2023-30515 | HIGH | 7.5 | 0.4% | Apr 12, 2023 | Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) cre... |
| CVE-2023-30514 | HIGH | 7.5 | 0.5% | Apr 12, 2023 | Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) cre... |
| CVE-2023-30513 | HIGH | 7.5 | 0.5% | Apr 12, 2023 | Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentia... |
| CVE-2023-27216 | HIGH | 8.8 | 4.5% | Apr 12, 2023 | An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the net... |
| CVE-2023-26852 | HIGH | 7.2 | 2.0% | Apr 12, 2023 | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute ... |
| CVE-2023-0006 | MEDIUM | 6.3 | 0.1% | Apr 12, 2023 | A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to del... |
| CVE-2023-0005 | MEDIUM | 4.9 | 0.3% | Apr 12, 2023 | A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext val... |
| CVE-2023-0004 | MEDIUM | 6.5 | 1.1% | Apr 12, 2023 | A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to dele... |
| CVE-2023-29581 | MEDIUM | 5.5 | 0.3% | Apr 12, 2023 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE:... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now