2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23621 | HIGH | 7.5 | 0.9% | Jan 28, 2023 | Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o... |
| CVE-2023-23617 | HIGH | 7.5 | 1.0% | Jan 28, 2023 | OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code... |
| CVE-2023-0555 | HIGH | 8.1 | 0.6% | Jan 27, 2023 | The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o... |
| CVE-2023-0554 | HIGH | 8.1 | 0.4% | Jan 27, 2023 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ... |
| CVE-2023-0550 | HIGH | 8.1 | 0.7% | Jan 27, 2023 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and ... |
| CVE-2023-22242 | HIGH | 7.8 | 0.5% | Jan 27, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are ... |
| CVE-2023-22241 | HIGH | 7.8 | 0.4% | Jan 27, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are ... |
| CVE-2023-22240 | HIGH | 7.8 | 0.4% | Jan 27, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are ... |
| CVE-2023-0493 | HIGH | 8.8 | 7.9% | Jan 26, 2023 | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. |
| CVE-2023-0509 | HIGH | 7.4 | 0.5% | Jan 26, 2023 | Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44. |
| CVE-2023-0455 | HIGH | 8.8 | 5.7% | Jan 26, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. |
| CVE-2023-24458 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to conn... |
| CVE-2023-24452 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers... |
| CVE-2023-24447 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers t... |
| CVE-2023-24446 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick use... |
| CVE-2023-24437 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlie... |
| CVE-2023-24434 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allow... |
| CVE-2023-24432 | HIGH | 8.8 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers... |
| CVE-2023-24426 | HIGH | 8.8 | 1.0% | Jan 26, 2023 | Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login. |
| CVE-2023-24424 | HIGH | 8.8 | 1.2% | Jan 26, 2023 | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. |
| CVE-2023-24422 | HIGH | 8.8 | 0.6% | Jan 26, 2023 | A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and ear... |
| CVE-2023-24057 | HIGH | 8.1 | 1.2% | Jan 26, 2023 | HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via d... |
| CVE-2023-23619 | HIGH | 8.8 | 1.1% | Jan 26, 2023 | Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Ve... |
| CVE-2023-23614 | HIGH | 8.8 | 1.0% | Jan 26, 2023 | Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and ab... |
| CVE-2023-23612 | HIGH | 8.8 | 0.8% | Jan 26, 2023 | OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained f... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now