2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38258MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5, macOS Monterey 12.6.8. Processi...
CVE-2023-32442MEDIUM5.5An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.5, macOS Monter...
CVE-2023-32429MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass Pr...
CVE-2023-32416MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPa...
CVE-2023-38606MEDIUM5.5This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iP...
CVE-2023-38133MEDIUM6.5The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 1...
CVE-2023-36862MEDIUM5.5A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu...
CVE-2023-35983MEDIUM5.5This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5...
CVE-2023-28014MEDIUM5.4HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scrip...
CVE-2023-28013MEDIUM6.1HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering craf...
CVE-2023-37732MEDIUM5.5Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacke...
CVE-2023-37692MEDIUM5.4An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted fi...
CVE-2023-37624MEDIUM6.1Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnera...
CVE-2023-37623MEDIUM4.8Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/Ty...
CVE-2023-33802MEDIUM5.5A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text fil...
CVE-2023-31466MEDIUM5.4An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance re...
CVE-2023-3414MEDIUM6.5A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38...
CVE-2023-3242MEDIUM5.9Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows ...
CVE-2023-30949MEDIUM5.3A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which ...
CVE-2023-3622MEDIUM4.3 Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary r...
CVE-2023-39156MEDIUM5.3A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete p...
CVE-2023-39155MEDIUM5.3Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a...
CVE-2023-39154MEDIUM6.5Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with ...
CVE-2023-39153MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows atta...
CVE-2023-39152MEDIUM6.5Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now