2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6774MEDIUM5.4A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected b...
CVE-2023-50441MEDIUM5.5Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTR...
CVE-2023-49296MEDIUM6.1The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino...
CVE-2023-6795MEDIUM4.7An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to di...
CVE-2023-6794MEDIUM4.7An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write adminis...
CVE-2023-6792MEDIUM6.3An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API ...
CVE-2023-6791MEDIUM4.9A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administr...
CVE-2023-6790MEDIUM6.1A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to ...
CVE-2023-6789MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-...
CVE-2023-6767MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects...
CVE-2023-50779MEDIUM4.3Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permis...
CVE-2023-50777MEDIUM4.3Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job con...
CVE-2023-50776MEDIUM4.3Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml f...
CVE-2023-50775MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac...
CVE-2023-50773MEDIUM4.3Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form,...
CVE-2023-50772MEDIUM4.3Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenk...
CVE-2023-50771MEDIUM6.1Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is le...
CVE-2023-50770MEDIUM6.7Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-l...
CVE-2023-50769MEDIUM4.3Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permi...
CVE-2023-50767MEDIUM5.4Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permi...
CVE-2023-50765MEDIUM4.3A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read...
CVE-2023-6762MEDIUM4.3A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of...
CVE-2023-6760MEDIUM5.4A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code....
CVE-2023-6758MEDIUM4.3A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown...
CVE-2023-6757MEDIUM6.5A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now