2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2509 | MEDIUM | 6.1 | 0.3% | May 17, 2023 | A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this ... |
| CVE-2023-2608 | MEDIUM | 4.3 | 0.4% | May 17, 2023 | The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL I... |
| CVE-2023-31847 | MEDIUM | 6.5 | 0.6% | May 17, 2023 | In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source ... |
| CVE-2023-1764 | MEDIUM | 6.5 | 0.2% | May 17, 2023 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (... |
| CVE-2023-1763 | MEDIUM | 6.5 | 0.3% | May 17, 2023 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (... |
| CVE-2023-30452 | MEDIUM | 5.4 | 0.3% | May 17, 2023 | The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map wi... |
| CVE-2023-31678 | MEDIUM | 5.3 | 0.6% | May 16, 2023 | Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended. |
| CVE-2023-31544 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web... |
| CVE-2023-30281 | MEDIUM | 6.5 | 0.5% | May 16, 2023 | Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3... |
| CVE-2023-29927 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privilege... |
| CVE-2023-30510 | MEDIUM | 4.3 | 0.6% | May 16, 2023 | A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated use... |
| CVE-2023-30509 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-30508 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-30507 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-2631 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to ... |
| CVE-2023-2633 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, incr... |
| CVE-2023-2632 | MEDIUM | 4.3 | 0.6% | May 16, 2023 | Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenki... |
| CVE-2023-2196 | MEDIUM | 4.3 | 1.0% | May 16, 2023 | A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to che... |
| CVE-2023-33007 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cr... |
| CVE-2023-33006 | MEDIUM | 5.4 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick... |
| CVE-2023-33005 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. |
| CVE-2023-33004 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission ... |
| CVE-2023-33003 | MEDIUM | 4.3 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to res... |
| CVE-2023-33002 | MEDIUM | 5.4 | 2.4% | May 16, 2023 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stor... |
| CVE-2023-32999 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now