2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28679 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a p... |
| CVE-2023-28678 | MEDIUM | 5.4 | 0.5% | Apr 2, 2023 | Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on th... |
| CVE-2023-28677 | CRITICAL | 9.8 | 0.8% | Apr 2, 2023 | Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build ... |
| CVE-2023-28676 | HIGH | 8.8 | 0.6% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers... |
| CVE-2023-28675 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect ... |
| CVE-2023-28674 | HIGH | 8.8 | 0.4% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allow... |
| CVE-2023-28673 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overal... |
| CVE-2023-28672 | MEDIUM | 6.5 | 0.5% | Apr 2, 2023 | Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test H... |
| CVE-2023-28671 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allow... |
| CVE-2023-28670 | MEDIUM | 5.4 | 0.5% | Apr 2, 2023 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL ... |
| CVE-2023-28669 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cr... |
| CVE-2023-28668 | CRITICAL | 9.8 | 0.8% | Apr 2, 2023 | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've be... |
| CVE-2023-27286 | CRITICAL | 9.8 | 0.7% | Apr 2, 2023 | IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds check... |
| CVE-2023-27284 | CRITICAL | 9.8 | 0.7% | Apr 2, 2023 | IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds check... |
| CVE-2023-26283 | MEDIUM | 5.4 | 0.4% | Apr 2, 2023 | IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2023-20559 | HIGH | 8.8 | 0.7% | Apr 2, 2023 | Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM hand... |
| CVE-2023-20558 | HIGH | 8.8 | 0.7% | Apr 2, 2023 | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler pot... |
| CVE-2023-1603 | MEDIUM | 6.5 | 0.6% | Apr 2, 2023 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior ver... |
| CVE-2023-1598 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-1580 | HIGH | 7.5 | 0.6% | Apr 2, 2023 | Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker ... |
| CVE-2023-1574 | MEDIUM | 6.5 | 0.5% | Apr 2, 2023 | Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.... |
| CVE-2023-1202 | MEDIUM | 6.5 | 0.4% | Apr 2, 2023 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9... |
| CVE-2023-1800 | CRITICAL | 9.8 | 3.5% | Apr 2, 2023 | A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this i... |
| CVE-2023-1799 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of ... |
| CVE-2023-1798 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is s... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now