2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39711 | MEDIUM | 6.1 | 0.5% | Sep 7, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta... |
| CVE-2023-3747 | MEDIUM | 5.5 | 0.2% | Sep 7, 2023 | Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes ca... |
| CVE-2023-36635 | MEDIUM | 4.3 | 0.4% | Sep 7, 2023 | An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r... |
| CVE-2023-4792 | MEDIUM | 4.3 | 0.4% | Sep 7, 2023 | The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplica... |
| CVE-2023-4772 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in ... |
| CVE-2023-41329 | MEDIUM | 6.6 | 0.6% | Sep 6, 2023 | WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions c... |
| CVE-2023-41327 | MEDIUM | 5.4 | 0.5% | Sep 6, 2023 | WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recordin... |
| CVE-2023-39956 | MEDIUM | 6.6 | 0.6% | Sep 6, 2023 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro... |
| CVE-2023-41601 | MEDIUM | 6.1 | 0.4% | Sep 6, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute ar... |
| CVE-2023-39511 | MEDIUM | 4.8 | 0.7% | Sep 6, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored... |
| CVE-2023-38486 | MEDIUM | 6.4 | 0.3% | Sep 6, 2023 | A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows... |
| CVE-2023-38485 | MEDIUM | 6.4 | 0.4% | Sep 6, 2023 | Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow... |
| CVE-2023-38484 | MEDIUM | 6.4 | 0.4% | Sep 6, 2023 | Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow... |
| CVE-2023-20263 | MEDIUM | 6.1 | 0.5% | Sep 6, 2023 | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated... |
| CVE-2023-4498 | MEDIUM | 5.3 | 0.4% | Sep 6, 2023 | Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to aut... |
| CVE-2023-39265 | MEDIUM | 6.5 | 83.7% | Sep 6, 2023 | Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati... |
| CVE-2023-37941 | MEDIUM | 6.6 | 29.2% | Sep 6, 2023 | If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py... |
| CVE-2023-32672 | MEDIUM | 4.3 | 0.7% | Sep 6, 2023 | An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all... |
| CVE-2023-41947 | MEDIUM | 4.3 | 0.4% | Sep 6, 2023 | A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permissio... |
| CVE-2023-41944 | MEDIUM | 6.1 | 0.4% | Sep 6, 2023 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form valid... |
| CVE-2023-41943 | MEDIUM | 6.5 | 0.5% | Sep 6, 2023 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi... |
| CVE-2023-41942 | MEDIUM | 4.3 | 0.3% | Sep 6, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows att... |
| CVE-2023-41941 | MEDIUM | 4.3 | 0.4% | Sep 6, 2023 | A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Rea... |
| CVE-2023-41940 | MEDIUM | 5.4 | 0.5% | Sep 6, 2023 | Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) v... |
| CVE-2023-41938 | MEDIUM | 6.5 | 0.3% | Sep 6, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disab... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now