2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22740 | MEDIUM | 6.5 | 0.7% | Jan 27, 2023 | Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are v... |
| CVE-2023-0519 | MEDIUM | 5.4 | 0.5% | Jan 26, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-0493 | HIGH | 8.8 | 7.9% | Jan 26, 2023 | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. |
| CVE-2023-0509 | HIGH | 7.4 | 0.5% | Jan 26, 2023 | Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44. |
| CVE-2023-0488 | MEDIUM | 5.4 | 0.8% | Jan 26, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42. |
| CVE-2023-0470 | MEDIUM | 5.4 | 0.6% | Jan 26, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-0455 | HIGH | 8.8 | 5.7% | Jan 26, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. |
| CVE-2023-24508 | CRITICAL | 9.6 | 1.6% | Jan 26, 2023 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vu... |
| CVE-2023-24495 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-acc... |
| CVE-2023-24494 | MEDIUM | 5.4 | 0.7% | Jan 26, 2023 | A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input... |
| CVE-2023-24493 | MEDIUM | 5.7 | 0.7% | Jan 26, 2023 | A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returnin... |
| CVE-2023-24459 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission t... |
| CVE-2023-24458 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to conn... |
| CVE-2023-24457 | MEDIUM | 6.5 | 1.0% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows att... |
| CVE-2023-24456 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login. |
| CVE-2023-24455 | MEDIUM | 4.3 | 1.2% | Jan 26, 2023 | Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation... |
| CVE-2023-24454 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global con... |
| CVE-2023-24453 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to c... |
| CVE-2023-24452 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers... |
| CVE-2023-24451 | MEDIUM | 4.3 | 0.6% | Jan 26, 2023 | A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read p... |
| CVE-2023-24450 | MEDIUM | 6.5 | 0.6% | Jan 26, 2023 | Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controlle... |
| CVE-2023-24449 | MEDIUM | 4.3 | 1.2% | Jan 26, 2023 | Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form v... |
| CVE-2023-24448 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permis... |
| CVE-2023-24447 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers t... |
| CVE-2023-24446 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick use... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now