2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23461 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | Libpeconv – access violation, before commit b076013 (30/11/2022). |
| CVE-2023-23460 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. |
| CVE-2023-23459 | CRITICAL | 9.8 | 0.9% | Feb 15, 2023 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. |
| CVE-2023-23458 | MEDIUM | 6.5 | 0.5% | Feb 15, 2023 | Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified r... |
| CVE-2023-22807 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal ... |
| CVE-2023-22806 | HIGH | 7.5 | 0.4% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicatin... |
| CVE-2023-22805 | MEDIUM | 4.3 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. T... |
| CVE-2023-22804 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This cou... |
| CVE-2023-22803 | HIGH | 7.5 | 0.6% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the... |
| CVE-2023-0361 | HIGH | 7.4 | 1.4% | Feb 15, 2023 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can ... |
| CVE-2023-0103 | HIGH | 7.5 | 0.7% | Feb 15, 2023 | If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are out... |
| CVE-2023-0102 | CRITICAL | 9.1 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could... |
| CVE-2023-25578 | HIGH | 7.5 | 1.0% | Feb 15, 2023 | Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing ... |
| CVE-2023-25192 | MEDIUM | 5.3 | 0.5% | Feb 15, 2023 | AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat... |
| CVE-2023-25191 | HIGH | 7.5 | 0.6% | Feb 15, 2023 | AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-... |
| CVE-2023-25171 | MEDIUM | 5.9 | 0.9% | Feb 15, 2023 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e... |
| CVE-2023-25156 | CRITICAL | 9.8 | 0.9% | Feb 15, 2023 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e... |
| CVE-2023-25768 | MEDIUM | 6.5 | 0.6% | Feb 15, 2023 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa... |
| CVE-2023-25767 | HIGH | 8.8 | 0.5% | Feb 15, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allo... |
| CVE-2023-25766 | MEDIUM | 4.3 | 0.5% | Feb 15, 2023 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa... |
| CVE-2023-25765 | CRITICAL | 9.9 | 1.1% | Feb 15, 2023 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Securit... |
| CVE-2023-25764 | MEDIUM | 5.4 | 0.6% | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or ... |
| CVE-2023-25763 | MEDIUM | 5.4 | 0.6% | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resu... |
| CVE-2023-25762 | MEDIUM | 5.4 | 81.4% | Feb 15, 2023 | Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pi... |
| CVE-2023-25761 | MEDIUM | 5.4 | 0.7% | Feb 15, 2023 | Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, re... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now