2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39044MEDIUM6.5An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted...
CVE-2023-20597MEDIUM5.5Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc...
CVE-2023-20594MEDIUM4.4Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc...
CVE-2023-43502MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta...
CVE-2023-43501MEDIUM6.5A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read...
CVE-2023-43499MEDIUM5.4Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in ...
CVE-2023-43495MEDIUM5.4Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of '...
CVE-2023-43494MEDIUM4.3Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive buil...
CVE-2023-42656MEDIUM6.1 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...
CVE-2023-2508MEDIUM6.5The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attac...
CVE-2023-5084MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
CVE-2023-34047MEDIUM4.3A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context...
CVE-2023-22644MEDIUM5.5A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ...
CVE-2023-43621MEDIUM4.7An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users ...
CVE-2023-43618MEDIUM5.3An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in clear...
CVE-2023-43617MEDIUM5.3An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge ...
CVE-2023-43616MEDIUM5.5An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
CVE-2023-26144MEDIUM5.3Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insuffici...
CVE-2023-5063MEDIUM5.4The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortc...
CVE-2023-5062MEDIUM5.4The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in vers...
CVE-2023-31014MEDIUM4.8NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on...
CVE-2023-25526MEDIUM6.5NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may ca...
CVE-2023-39575MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attacke...
CVE-2023-40932MEDIUM5.4A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with acc...
CVE-2023-40931MEDIUM6.5A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now