2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29198 | HIGH | 8.5 | 0.5% | Sep 6, 2023 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro... |
| CVE-2023-4809 | HIGH | 7.5 | 0.7% | Sep 6, 2023 | In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers woul... |
| CVE-2023-40591 | HIGH | 7.5 | 1.0% | Sep 6, 2023 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made t... |
| CVE-2023-41328 | HIGH | 7.5 | 0.4% | Sep 6, 2023 | Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified i... |
| CVE-2023-41319 | HIGH | 7.2 | 0.8% | Sep 6, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ... |
| CVE-2023-41050 | HIGH | 7.7 | 0.5% | Sep 6, 2023 | AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone cont... |
| CVE-2023-20243 | HIGH | 8.6 | 0.8% | Sep 6, 2023 | A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen... |
| CVE-2023-20250 | HIGH | 7.2 | 0.8% | Sep 6, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers ... |
| CVE-2023-4623 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be e... |
| CVE-2023-4622 | HIGH | 7 | 0.5% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escal... |
| CVE-2023-4244 | HIGH | 7 | 0.2% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-4208 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv... |
| CVE-2023-4207 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi... |
| CVE-2023-4206 | HIGH | 7.8 | 0.6% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local pr... |
| CVE-2023-4015 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-3777 | HIGH | 7.8 | 0.4% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-41945 | HIGH | 8.8 | 0.6% | Sep 6, 2023 | Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in u... |
| CVE-2023-41939 | HIGH | 8.8 | 0.6% | Sep 6, 2023 | Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentia... |
| CVE-2023-41937 | HIGH | 7.5 | 0.6% | Sep 6, 2023 | Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhoo... |
| CVE-2023-41936 | HIGH | 7.5 | 0.7% | Sep 6, 2023 | Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provi... |
| CVE-2023-41935 | HIGH | 7.5 | 0.7% | Sep 6, 2023 | Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time compari... |
| CVE-2023-41933 | HIGH | 8.8 | 0.8% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XM... |
| CVE-2023-4589 | HIGH | 7.2 | 0.3% | Sep 6, 2023 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An a... |
| CVE-2023-40531 | HIGH | 8 | 0.4% | Sep 6, 2023 | Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authentic... |
| CVE-2023-40357 | HIGH | 8 | 0.4% | Sep 6, 2023 | Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now