2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37560 | MEDIUM | 6.1 | 0.4% | Jul 13, 2023 | Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote un... |
| CVE-2023-2190 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions st... |
| CVE-2023-34125 | MEDIUM | 6.5 | 22.7% | Jul 13, 2023 | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the unde... |
| CVE-2023-21260 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In notification access permission dialog box, malicious application can embedded a very long service label that overflow... |
| CVE-2023-35693 | MEDIUM | 6.7 | 0.1% | Jul 13, 2023 | In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to lo... |
| CVE-2023-21400 | MEDIUM | 6.7 | 0.3% | Jul 13, 2023 | In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could l... |
| CVE-2023-21249 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a p... |
| CVE-2023-21243 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file... |
| CVE-2023-21240 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of s... |
| CVE-2023-21239 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused d... |
| CVE-2023-21238 | MEDIUM | 5.5 | 0.2% | Jul 13, 2023 | In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could ... |
| CVE-2023-20942 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy... |
| CVE-2023-3642 | MEDIUM | 6.1 | 0.4% | Jul 12, 2023 | A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issu... |
| CVE-2023-3641 | MEDIUM | 6.1 | 0.4% | Jul 12, 2023 | A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability i... |
| CVE-2023-38046 | MEDIUM | 4.9 | 0.4% | Jul 12, 2023 | A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privil... |
| CVE-2023-37630 | MEDIUM | 6.1 | 0.5% | Jul 12, 2023 | Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaS... |
| CVE-2023-37963 | MEDIUM | 5.4 | 0.4% | Jul 12, 2023 | A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read pe... |
| CVE-2023-37960 | MEDIUM | 6.5 | 1.0% | Jul 12, 2023 | Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with... |
| CVE-2023-37959 | MEDIUM | 6.5 | 0.5% | Jul 12, 2023 | A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read pe... |
| CVE-2023-37956 | MEDIUM | 6.5 | 0.5% | Jul 12, 2023 | A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Re... |
| CVE-2023-37955 | MEDIUM | 6.5 | 0.4% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows at... |
| CVE-2023-37954 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Rebuilder Plugin 320.v5a_0933a_e7d61 and earlier allows att... |
| CVE-2023-37953 | MEDIUM | 6.5 | 0.6% | Jul 12, 2023 | A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to co... |
| CVE-2023-37952 | MEDIUM | 6.5 | 0.4% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect ... |
| CVE-2023-37951 | MEDIUM | 6.5 | 0.6% | Jul 12, 2023 | Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers w... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now