2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4693 | MEDIUM | 4.6 | 0.5% | Oct 25, 2023 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attack... |
| CVE-2023-46660 | MEDIUM | 5.3 | 0.5% | Oct 25, 2023 | Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided an... |
| CVE-2023-46659 | MEDIUM | 5.4 | 0.5% | Oct 25, 2023 | Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a sto... |
| CVE-2023-46658 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whet... |
| CVE-2023-46657 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided a... |
| CVE-2023-46656 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when chec... |
| CVE-2023-46655 | MEDIUM | 6.5 | 1.2% | Oct 25, 2023 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which a... |
| CVE-2023-46653 | MEDIUM | 6.5 | 0.4% | Oct 25, 2023 | Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, pot... |
| CVE-2023-46652 | MEDIUM | 4.3 | 0.4% | Oct 25, 2023 | A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read... |
| CVE-2023-46651 | MEDIUM | 6.5 | 0.6% | Oct 25, 2023 | Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attacke... |
| CVE-2023-46650 | MEDIUM | 5.4 | 0.6% | Oct 25, 2023 | Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, ... |
| CVE-2023-46396 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search fil... |
| CVE-2023-46316 | MEDIUM | 5.5 | 0.4% | Oct 25, 2023 | In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines. |
| CVE-2023-46128 | MEDIUM | 6.5 | 0.5% | Oct 25, 2023 | Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL ... |
| CVE-2023-46126 | MEDIUM | 5.4 | 0.6% | Oct 25, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime en... |
| CVE-2023-46125 | MEDIUM | 6.5 | 0.7% | Oct 25, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ... |
| CVE-2023-46123 | MEDIUM | 5.3 | 0.7% | Oct 25, 2023 | jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies... |
| CVE-2023-46118 | MEDIUM | 4.9 | 1.1% | Oct 25, 2023 | RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making... |
| CVE-2023-46071 | MEDIUM | 6.1 | 0.4% | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versio... |
| CVE-2023-46070 | MEDIUM | 6.1 | 0.4% | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Emmanuel GEORJON EG-Attachments plugin <= 2.1.3 versions. |
| CVE-2023-46069 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.... |
| CVE-2023-46068 | MEDIUM | 4.8 | 0.4% | Oct 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XQueue GmbH Maileon for WordPress plugin <= 2.16.0 ver... |
| CVE-2023-45844 | MEDIUM | 6.8 | 0.3% | Oct 25, 2023 | The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an ar... |
| CVE-2023-45837 | MEDIUM | 6.1 | 0.4% | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions. |
| CVE-2023-45835 | MEDIUM | 6.1 | 0.4% | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Libsyn Libsyn Publisher Hub plugin <= 1.4.4 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now