2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23461CRITICAL9.8Libpeconv – access violation, before commit b076013 (30/11/2022).
CVE-2023-23460CRITICAL9.8Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
CVE-2023-23459CRITICAL9.8Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
CVE-2023-23458MEDIUM6.5Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified r...
CVE-2023-22807CRITICAL9.8LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal ...
CVE-2023-22806HIGH7.5LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicatin...
CVE-2023-22805MEDIUM4.3LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. T...
CVE-2023-22804CRITICAL9.8LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This cou...
CVE-2023-22803HIGH7.5LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the...
CVE-2023-0361HIGH7.4A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can ...
CVE-2023-0103HIGH7.5If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are out...
CVE-2023-0102CRITICAL9.1LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could...
CVE-2023-25578HIGH7.5Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing ...
CVE-2023-25192MEDIUM5.3AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat...
CVE-2023-25191HIGH7.5AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-...
CVE-2023-25171MEDIUM5.9Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e...
CVE-2023-25156CRITICAL9.8Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e...
CVE-2023-25768MEDIUM6.5A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa...
CVE-2023-25767HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allo...
CVE-2023-25766MEDIUM4.3A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa...
CVE-2023-25765CRITICAL9.9In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Securit...
CVE-2023-25764MEDIUM5.4Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or ...
CVE-2023-25763MEDIUM5.4Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resu...
CVE-2023-25762MEDIUM5.4Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pi...
CVE-2023-25761MEDIUM5.4Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, re...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now