2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-20111MEDIUM6.5A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2023-40021MEDIUM5.3Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the st...
CVE-2023-20242MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2023-20228MEDIUM6.1A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an una...
CVE-2023-4384MEDIUM5.9A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerabili...
CVE-2023-4382MEDIUM5.4A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. Affected by this issue is so...
CVE-2023-28075MEDIUM6.3 Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical...
CVE-2023-4385MEDIUM5.5A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linu...
CVE-2023-39250MEDIUM5.5 Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6....
CVE-2023-2737MEDIUM5.5Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to ...
CVE-2023-40351MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Favorite View Plugin 5.v77a_37f62782d and earlier allows at...
CVE-2023-40350MEDIUM5.4Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the ...
CVE-2023-40349MEDIUM5.3Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthe...
CVE-2023-40348MEDIUM5.3The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the ...
CVE-2023-40347MEDIUM6.5Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for crede...
CVE-2023-40346MEDIUM5.4Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-si...
CVE-2023-40345MEDIUM6.5Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers...
CVE-2023-40344MEDIUM4.3A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to ...
CVE-2023-40343MEDIUM5.9Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an ...
CVE-2023-40342MEDIUM5.4Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins...
CVE-2023-40338MEDIUM4.3Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log...
CVE-2023-40337MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attac...
CVE-2023-38904MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code ...
CVE-2023-32491MEDIUM6.5 Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A ...
CVE-2023-32490MEDIUM6.7 Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attack...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now