2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48951HIGH7.5An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service...
CVE-2023-48950HIGH7.5An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2023-48949HIGH7.5An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48948HIGH7.5An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48947HIGH7.5An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48946HIGH7.5An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48945HIGH7.5A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted...
CVE-2023-44383MEDIUM5.4October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to...
CVE-2023-49083HIGH7.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pe...
CVE-2023-49079HIGH7.5Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary ...
CVE-2023-6218HIGH7.2 In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privi...
CVE-2023-6217MEDIUM6.1 In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a refle...
CVE-2023-48882MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-48881MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-48880MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s...
CVE-2023-49090MEDIUM6.1CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-T...
CVE-2023-49674MEDIUM4.3A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Over...
CVE-2023-49673HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier all...
CVE-2023-49656CRITICAL9.8Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2023-49655HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have J...
CVE-2023-49654CRITICAL9.8Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file ...
CVE-2023-49653MEDIUM6.5Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers wit...
CVE-2023-49652LOW2.7Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers w...
CVE-2023-40626HIGH7.5The language file parsing process could be manipulated to expose environment variables. Environment variables might cont...
CVE-2023-6378HIGH7.5A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now