2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24445 | MEDIUM | 6.1 | 0.7% | Jan 26, 2023 | Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to ... |
| CVE-2023-24444 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login. |
| CVE-2023-24443 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2023-24442 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar acce... |
| CVE-2023-24441 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2023-24440 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of ... |
| CVE-2023-24439 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global c... |
| CVE-2023-24438 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with... |
| CVE-2023-24437 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlie... |
| CVE-2023-24436 | MEDIUM | 4.3 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal... |
| CVE-2023-24435 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal... |
| CVE-2023-24434 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allow... |
| CVE-2023-24433 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permis... |
| CVE-2023-24432 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers... |
| CVE-2023-24431 | MEDIUM | 4.3 | 0.6% | Jan 26, 2023 | A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read perm... |
| CVE-2023-24430 | CRITICAL | 9.8 | 1.3% | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2023-24429 | CRITICAL | 9.8 | 1.3% | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents... |
| CVE-2023-24428 | MEDIUM | 5.7 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to... |
| CVE-2023-24427 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. |
| CVE-2023-24426 | HIGH | 8.8 | 1.0% | Jan 26, 2023 | Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login. |
| CVE-2023-24425 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for ... |
| CVE-2023-24424 | HIGH | 8.8 | 1.2% | Jan 26, 2023 | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. |
| CVE-2023-24423 | MEDIUM | 6.5 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers t... |
| CVE-2023-24422 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and ear... |
| CVE-2023-24170 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now