2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28679MEDIUM5.4Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a p...
CVE-2023-28678MEDIUM5.4Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on th...
CVE-2023-28677CRITICAL9.8Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build ...
CVE-2023-28676HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers...
CVE-2023-28675MEDIUM4.3A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect ...
CVE-2023-28674HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allow...
CVE-2023-28673MEDIUM4.3A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overal...
CVE-2023-28672MEDIUM6.5Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test H...
CVE-2023-28671MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allow...
CVE-2023-28670MEDIUM5.4Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL ...
CVE-2023-28669MEDIUM5.4Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cr...
CVE-2023-28668CRITICAL9.8Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've be...
CVE-2023-27286CRITICAL9.8IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds check...
CVE-2023-27284CRITICAL9.8IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds check...
CVE-2023-26283MEDIUM5.4IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2023-20559HIGH8.8 Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM hand...
CVE-2023-20558HIGH8.8 Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler pot...
CVE-2023-1603MEDIUM6.5 Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior ver...
CVE-2023-1598Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-1580HIGH7.5Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker ...
CVE-2023-1574MEDIUM6.5Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1....
CVE-2023-1202MEDIUM6.5Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9...
CVE-2023-1800CRITICAL9.8A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this i...
CVE-2023-1799MEDIUM5.4A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of ...
CVE-2023-1798MEDIUM5.4A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is s...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now