2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48951 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service... |
| CVE-2023-48950 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2023-48949 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48948 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48947 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48946 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48945 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted... |
| CVE-2023-44383 | MEDIUM | 5.4 | 0.4% | Nov 29, 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to... |
| CVE-2023-49083 | HIGH | 7.5 | 1.0% | Nov 29, 2023 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pe... |
| CVE-2023-49079 | HIGH | 7.5 | 0.4% | Nov 29, 2023 | Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary ... |
| CVE-2023-6218 | HIGH | 7.2 | 0.7% | Nov 29, 2023 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privi... |
| CVE-2023-6217 | MEDIUM | 6.1 | 0.5% | Nov 29, 2023 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a refle... |
| CVE-2023-48882 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-48881 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-48880 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-49090 | MEDIUM | 6.1 | 0.6% | Nov 29, 2023 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-T... |
| CVE-2023-49674 | MEDIUM | 4.3 | 0.5% | Nov 29, 2023 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Over... |
| CVE-2023-49673 | HIGH | 8.8 | 0.4% | Nov 29, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier all... |
| CVE-2023-49656 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2023-49655 | HIGH | 8.8 | 0.4% | Nov 29, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have J... |
| CVE-2023-49654 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file ... |
| CVE-2023-49653 | MEDIUM | 6.5 | 0.6% | Nov 29, 2023 | Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers wit... |
| CVE-2023-49652 | LOW | 2.7 | 0.5% | Nov 29, 2023 | Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers w... |
| CVE-2023-40626 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might cont... |
| CVE-2023-6378 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now