2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41934 | MEDIUM | 5.3 | 0.5% | Sep 6, 2023 | Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with aste... |
| CVE-2023-41932 | MEDIUM | 6.5 | 0.6% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters ... |
| CVE-2023-41931 | MEDIUM | 5.4 | 0.4% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timest... |
| CVE-2023-41930 | MEDIUM | 4.3 | 0.8% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter wh... |
| CVE-2023-41150 | MEDIUM | 5.4 | 0.3% | Sep 6, 2023 | F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is explo... |
| CVE-2023-39264 | MEDIUM | 4.3 | 0.8% | Sep 6, 2023 | By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoint... |
| CVE-2023-36388 | MEDIUM | 5.4 | 0.8% | Sep 6, 2023 | Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to tes... |
| CVE-2023-36387 | MEDIUM | 5.4 | 0.8% | Sep 6, 2023 | An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authe... |
| CVE-2023-27526 | MEDIUM | 4.3 | 0.9% | Sep 6, 2023 | A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up... |
| CVE-2023-27523 | MEDIUM | 4.3 | 0.7% | Sep 6, 2023 | Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an ... |
| CVE-2023-4588 | MEDIUM | 4.9 | 0.3% | Sep 6, 2023 | File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation o... |
| CVE-2023-40601 | MEDIUM | 6.1 | 0.3% | Sep 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versio... |
| CVE-2023-40560 | MEDIUM | 4.8 | 0.3% | Sep 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versio... |
| CVE-2023-40554 | MEDIUM | 6.1 | 0.4% | Sep 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post &... |
| CVE-2023-40553 | MEDIUM | 6.1 | 0.3% | Sep 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Plausible.Io Plausible Analytics plugin <= 1.3.3 versions. |
| CVE-2023-40552 | MEDIUM | 4.8 | 0.3% | Sep 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gurcharan Singh Fitness calculators plugin plugin <= 2... |
| CVE-2023-40329 | MEDIUM | 4.8 | 0.3% | Sep 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPZest Custom Admin Login Page | WPZest plugin <= 1.2.... |
| CVE-2023-40328 | MEDIUM | 4.8 | 0.3% | Sep 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Carrrot plugin <= 1.1.0 versions. |
| CVE-2023-40007 | MEDIUM | 4.8 | 0.3% | Sep 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ujwol Bastakoti CT Commerce plugin <= 2.0.1 versions. |
| CVE-2023-30497 | MEDIUM | 6.1 | 0.3% | Sep 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions. |
| CVE-2023-29441 | MEDIUM | 6.1 | 0.3% | Sep 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions. |
| CVE-2023-4779 | MEDIUM | 5.4 | 0.3% | Sep 6, 2023 | The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery... |
| CVE-2023-35719 | MEDIUM | 6.8 | 20.2% | Sep 6, 2023 | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnera... |
| CVE-2023-4773 | MEDIUM | 6.4 | 0.4% | Sep 6, 2023 | The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_l... |
| CVE-2023-30730 | MEDIUM | 5.5 | 0.1% | Sep 6, 2023 | Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now