2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23328 | HIGH | 8.8 | 1.1% | Mar 10, 2023 | A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileU... |
| CVE-2023-23327 | MEDIUM | 4.9 | 0.8% | Mar 10, 2023 | An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and datab... |
| CVE-2023-23326 | MEDIUM | 5.4 | 0.5% | Mar 10, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inje... |
| CVE-2023-27905 | CRITICAL | 9.6 | 1.5% | Mar 10, 2023 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sa... |
| CVE-2023-27904 | MEDIUM | 5.3 | 0.7% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connect... |
| CVE-2023-27903 | MEDIUM | 4.4 | 0.2% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the ... |
| CVE-2023-27902 | MEDIUM | 4.3 | 0.7% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows a... |
| CVE-2023-27901 | HIGH | 7.5 | 1.0% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits ... |
| CVE-2023-27900 | HIGH | 7.5 | 1.0% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits ... |
| CVE-2023-27899 | HIGH | 7 | 0.2% | Mar 10, 2023 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the ... |
| CVE-2023-27898 | CRITICAL | 9.6 | 1.8% | Mar 10, 2023 | Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins v... |
| CVE-2023-27577 | MEDIUM | 4.9 | 0.9% | Mar 10, 2023 | flarum is a forum software package for building communities. In versions prior to 1.7.0 an admin account which has alrea... |
| CVE-2023-25148 | HIGH | 7.8 | 0.4% | Mar 10, 2023 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulner... |
| CVE-2023-25147 | MEDIUM | 6.7 | 0.2% | Mar 10, 2023 | An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via... |
| CVE-2023-25146 | HIGH | 7.8 | 0.4% | Mar 10, 2023 | A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quaranti... |
| CVE-2023-25145 | HIGH | 7.8 | 0.4% | Mar 10, 2023 | A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to es... |
| CVE-2023-25144 | HIGH | 7.8 | 0.3% | Mar 10, 2023 | An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated... |
| CVE-2023-25143 | CRITICAL | 9.8 | 1.7% | Mar 10, 2023 | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker t... |
| CVE-2023-24975 | MEDIUM | 6.1 | 0.4% | Mar 10, 2023 | IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he... |
| CVE-2023-1246 | HIGH | 7.5 | 0.6% | Mar 10, 2023 | Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common R... |
| CVE-2023-1203 | MEDIUM | 6.5 | 1.1% | Mar 10, 2023 | Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Man... |
| CVE-2023-1201 | MEDIUM | 6.5 | 0.8% | Mar 10, 2023 | Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated... |
| CVE-2023-1198 | CRITICAL | 9.8 | 0.7% | Mar 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities ... |
| CVE-2023-1173 | — | — | — | Mar 10, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-0193 | MEDIUM | 4.4 | 0.2% | Mar 10, 2023 | NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now