2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4693MEDIUM4.6An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attack...
CVE-2023-46660MEDIUM5.3Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided an...
CVE-2023-46659MEDIUM5.4Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a sto...
CVE-2023-46658MEDIUM5.3Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whet...
CVE-2023-46657MEDIUM5.3Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided a...
CVE-2023-46656MEDIUM5.3Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when chec...
CVE-2023-46655MEDIUM6.5Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which a...
CVE-2023-46653MEDIUM6.5Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, pot...
CVE-2023-46652MEDIUM4.3A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read...
CVE-2023-46651MEDIUM6.5Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attacke...
CVE-2023-46650MEDIUM5.4Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, ...
CVE-2023-46396MEDIUM5.4Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search fil...
CVE-2023-46316MEDIUM5.5In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
CVE-2023-46128MEDIUM6.5Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL ...
CVE-2023-46126MEDIUM5.4Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime en...
CVE-2023-46125MEDIUM6.5Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ...
CVE-2023-46123MEDIUM5.3jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies...
CVE-2023-46118MEDIUM4.9RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making...
CVE-2023-46071MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versio...
CVE-2023-46070MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Emmanuel GEORJON EG-Attachments plugin <= 2.1.3 versions.
CVE-2023-46069MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6....
CVE-2023-46068MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XQueue GmbH Maileon for WordPress plugin <= 2.16.0 ver...
CVE-2023-45844MEDIUM6.8The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an ar...
CVE-2023-45837MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.
CVE-2023-45835MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Libsyn Libsyn Publisher Hub plugin <= 1.4.4 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now