2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2509MEDIUM6.1A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this ...
CVE-2023-2608MEDIUM4.3The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL I...
CVE-2023-31847MEDIUM6.5In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source ...
CVE-2023-1764MEDIUM6.5Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (...
CVE-2023-1763MEDIUM6.5Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (...
CVE-2023-30452MEDIUM5.4The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map wi...
CVE-2023-31678MEDIUM5.3Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.
CVE-2023-31544MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web...
CVE-2023-30281MEDIUM6.5Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3...
CVE-2023-29927MEDIUM4.3Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privilege...
CVE-2023-30510MEDIUM4.3A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated use...
CVE-2023-30509MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-30508MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-30507MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-2631MEDIUM4.3A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to ...
CVE-2023-2633MEDIUM4.3Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, incr...
CVE-2023-2632MEDIUM4.3Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenki...
CVE-2023-2196MEDIUM4.3A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to che...
CVE-2023-33007MEDIUM5.4Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cr...
CVE-2023-33006MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick...
CVE-2023-33005MEDIUM5.4Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
CVE-2023-33004MEDIUM4.3A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission ...
CVE-2023-33003MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to res...
CVE-2023-33002MEDIUM5.4Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stor...
CVE-2023-32999MEDIUM4.3A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now