2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39711MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-3747MEDIUM5.5Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes ca...
CVE-2023-36635MEDIUM4.3An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r...
CVE-2023-4792MEDIUM4.3The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplica...
CVE-2023-4772MEDIUM5.4The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in ...
CVE-2023-41329MEDIUM6.6WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions c...
CVE-2023-41327MEDIUM5.4WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recordin...
CVE-2023-39956MEDIUM6.6Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro...
CVE-2023-41601MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute ar...
CVE-2023-39511MEDIUM4.8Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored...
CVE-2023-38486MEDIUM6.4A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows...
CVE-2023-38485MEDIUM6.4Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow...
CVE-2023-38484MEDIUM6.4Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow...
CVE-2023-20263MEDIUM6.1A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated...
CVE-2023-4498MEDIUM5.3Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to aut...
CVE-2023-39265MEDIUM6.5Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati...
CVE-2023-37941MEDIUM6.6If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py...
CVE-2023-32672MEDIUM4.3An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all...
CVE-2023-41947MEDIUM4.3A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permissio...
CVE-2023-41944MEDIUM6.1Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form valid...
CVE-2023-41943MEDIUM6.5Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi...
CVE-2023-41942MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows att...
CVE-2023-41941MEDIUM4.3A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Rea...
CVE-2023-41940MEDIUM5.4Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) v...
CVE-2023-41938MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disab...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now