2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39044 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted... |
| CVE-2023-20597 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc... |
| CVE-2023-20594 | MEDIUM | 4.4 | 0.2% | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc... |
| CVE-2023-43502 | MEDIUM | 4.3 | 0.3% | Sep 20, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta... |
| CVE-2023-43501 | MEDIUM | 6.5 | 0.5% | Sep 20, 2023 | A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read... |
| CVE-2023-43499 | MEDIUM | 5.4 | 0.5% | Sep 20, 2023 | Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in ... |
| CVE-2023-43495 | MEDIUM | 5.4 | 0.9% | Sep 20, 2023 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of '... |
| CVE-2023-43494 | MEDIUM | 4.3 | 3.4% | Sep 20, 2023 | Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive buil... |
| CVE-2023-42656 | MEDIUM | 6.1 | 0.5% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
| CVE-2023-2508 | MEDIUM | 6.5 | 0.2% | Sep 20, 2023 | The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attac... |
| CVE-2023-5084 | MEDIUM | 6.1 | 0.4% | Sep 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. |
| CVE-2023-34047 | MEDIUM | 4.3 | 0.4% | Sep 20, 2023 | A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context... |
| CVE-2023-22644 | MEDIUM | 5.5 | 0.5% | Sep 20, 2023 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ... |
| CVE-2023-43621 | MEDIUM | 4.7 | 0.3% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users ... |
| CVE-2023-43618 | MEDIUM | 5.3 | 0.4% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in clear... |
| CVE-2023-43617 | MEDIUM | 5.3 | 0.6% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge ... |
| CVE-2023-43616 | MEDIUM | 5.5 | 0.4% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction. |
| CVE-2023-26144 | MEDIUM | 5.3 | 1.2% | Sep 20, 2023 | Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insuffici... |
| CVE-2023-5063 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortc... |
| CVE-2023-5062 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in vers... |
| CVE-2023-31014 | MEDIUM | 4.8 | 0.1% | Sep 20, 2023 | NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on... |
| CVE-2023-25526 | MEDIUM | 6.5 | 0.3% | Sep 20, 2023 | NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may ca... |
| CVE-2023-39575 | MEDIUM | 5.4 | 0.3% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attacke... |
| CVE-2023-40932 | MEDIUM | 5.4 | 2.0% | Sep 19, 2023 | A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with acc... |
| CVE-2023-40931 | MEDIUM | 6.5 | 13.5% | Sep 19, 2023 | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now