2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-37560MEDIUM6.1Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote un...
CVE-2023-2190MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions st...
CVE-2023-34125MEDIUM6.5Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the unde...
CVE-2023-21260MEDIUM5.5In notification access permission dialog box, malicious application can embedded a very long service label that overflow...
CVE-2023-35693MEDIUM6.7In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to lo...
CVE-2023-21400MEDIUM6.7In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could l...
CVE-2023-21249MEDIUM5.5In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a p...
CVE-2023-21243MEDIUM5.5In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file...
CVE-2023-21240MEDIUM5.5In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of s...
CVE-2023-21239MEDIUM5.5In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused d...
CVE-2023-21238MEDIUM5.5In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could ...
CVE-2023-20942MEDIUM5.5In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy...
CVE-2023-3642MEDIUM6.1A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issu...
CVE-2023-3641MEDIUM6.1A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability i...
CVE-2023-38046MEDIUM4.9A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privil...
CVE-2023-37630MEDIUM6.1Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaS...
CVE-2023-37963MEDIUM5.4A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read pe...
CVE-2023-37960MEDIUM6.5Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with...
CVE-2023-37959MEDIUM6.5A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read pe...
CVE-2023-37956MEDIUM6.5A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Re...
CVE-2023-37955MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows at...
CVE-2023-37954MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Rebuilder Plugin 320.v5a_0933a_e7d61 and earlier allows att...
CVE-2023-37953MEDIUM6.5A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to co...
CVE-2023-37952MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect ...
CVE-2023-37951MEDIUM6.5Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers w...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now