2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32996 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Re... |
| CVE-2023-32993 | MEDIUM | 4.8 | 0.2% | May 16, 2023 | Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr... |
| CVE-2023-32990 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal... |
| CVE-2023-2740 | MEDIUM | 6.1 | 0.5% | May 16, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Guest Management System 1.0. Affe... |
| CVE-2023-32988 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal... |
| CVE-2023-32985 | MEDIUM | 4.3 | 72.4% | May 16, 2023 | Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validati... |
| CVE-2023-32984 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG r... |
| CVE-2023-32983 | MEDIUM | 5.3 | 0.4% | May 16, 2023 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form,... |
| CVE-2023-32982 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the ... |
| CVE-2023-32980 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another use... |
| CVE-2023-32979 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing at... |
| CVE-2023-32978 | MEDIUM | 4.3 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-spec... |
| CVE-2023-32977 | MEDIUM | 5.4 | 0.6% | May 16, 2023 | Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, r... |
| CVE-2023-2739 | MEDIUM | 6.1 | 0.4% | May 16, 2023 | A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affe... |
| CVE-2023-29439 | MEDIUM | 6.1 | 1.7% | May 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. |
| CVE-2023-2730 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. |
| CVE-2023-23720 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin... |
| CVE-2023-23709 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1 versions. |
| CVE-2023-23703 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1... |
| CVE-2023-23657 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe L... |
| CVE-2023-23641 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPmanage Uji Popup plugin <= 1.4.3 versions. |
| CVE-2023-23727 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Formilla Live Chat by Formilla plugin <= 1.3 versions. |
| CVE-2023-23676 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5... |
| CVE-2023-23673 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3.... |
| CVE-2023-2161 | MEDIUM | 5.5 | 0.2% | May 16, 2023 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized rea... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now