2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38258 | MEDIUM | 5.5 | 0.3% | Jul 27, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5, macOS Monterey 12.6.8. Processi... |
| CVE-2023-32442 | MEDIUM | 5.5 | 0.2% | Jul 27, 2023 | An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.5, macOS Monter... |
| CVE-2023-32429 | MEDIUM | 5.5 | 0.2% | Jul 27, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass Pr... |
| CVE-2023-32416 | MEDIUM | 5.5 | 0.2% | Jul 27, 2023 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPa... |
| CVE-2023-38606 | MEDIUM | 5.5 | 1.0% | Jul 27, 2023 | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iP... |
| CVE-2023-38133 | MEDIUM | 6.5 | 0.9% | Jul 27, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 1... |
| CVE-2023-36862 | MEDIUM | 5.5 | 0.2% | Jul 27, 2023 | A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu... |
| CVE-2023-35983 | MEDIUM | 5.5 | 0.2% | Jul 27, 2023 | This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5... |
| CVE-2023-28014 | MEDIUM | 5.4 | 0.2% | Jul 27, 2023 | HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scrip... |
| CVE-2023-28013 | MEDIUM | 6.1 | 0.3% | Jul 26, 2023 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering craf... |
| CVE-2023-37732 | MEDIUM | 5.5 | 0.3% | Jul 26, 2023 | Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacke... |
| CVE-2023-37692 | MEDIUM | 5.4 | 0.5% | Jul 26, 2023 | An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted fi... |
| CVE-2023-37624 | MEDIUM | 6.1 | 0.5% | Jul 26, 2023 | Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnera... |
| CVE-2023-37623 | MEDIUM | 4.8 | 0.5% | Jul 26, 2023 | Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/Ty... |
| CVE-2023-33802 | MEDIUM | 5.5 | 0.3% | Jul 26, 2023 | A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text fil... |
| CVE-2023-31466 | MEDIUM | 5.4 | 0.4% | Jul 26, 2023 | An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance re... |
| CVE-2023-3414 | MEDIUM | 6.5 | 0.4% | Jul 26, 2023 | A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38... |
| CVE-2023-3242 | MEDIUM | 5.9 | 0.5% | Jul 26, 2023 | Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows ... |
| CVE-2023-30949 | MEDIUM | 5.3 | 0.2% | Jul 26, 2023 | A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which ... |
| CVE-2023-3622 | MEDIUM | 4.3 | 0.7% | Jul 26, 2023 | Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary r... |
| CVE-2023-39156 | MEDIUM | 5.3 | 0.3% | Jul 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete p... |
| CVE-2023-39155 | MEDIUM | 5.3 | 0.4% | Jul 26, 2023 | Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a... |
| CVE-2023-39154 | MEDIUM | 6.5 | 0.5% | Jul 26, 2023 | Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with ... |
| CVE-2023-39153 | MEDIUM | 5.4 | 0.6% | Jul 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows atta... |
| CVE-2023-39152 | MEDIUM | 6.5 | 0.6% | Jul 26, 2023 | Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now