2023 CVE Vulnerabilities
31,250 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24724 | MEDIUM | 5.4 | 0.6% | Apr 3, 2023 | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Cons... |
| CVE-2023-1611 | MEDIUM | 6.3 | 0.2% | Apr 3, 2023 | A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows a... |
| CVE-2023-28851 | MEDIUM | 5.4 | 0.4% | Apr 3, 2023 | Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Start... |
| CVE-2023-28850 | MEDIUM | 5.4 | 0.6% | Apr 3, 2023 | Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspect... |
| CVE-2023-28837 | MEDIUM | 4.9 | 1.1% | Apr 3, 2023 | Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaust... |
| CVE-2023-28836 | MEDIUM | 5.4 | 0.8% | Apr 3, 2023 | Wagtail is an open source content management system built on Django. Starting in version 1.5 and prior to versions 4.1.4... |
| CVE-2023-28834 | MEDIUM | 4.3 | 0.8% | Apr 3, 2023 | Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, ... |
| CVE-2023-0977 | MEDIUM | 6.5 | 0.5% | Apr 3, 2023 | A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote use... |
| CVE-2023-1377 | MEDIUM | 6.1 | 0.5% | Apr 3, 2023 | The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back ... |
| CVE-2023-1330 | MEDIUM | 6.5 | 0.3% | Apr 3, 2023 | The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which c... |
| CVE-2023-0399 | MEDIUM | 5.4 | 0.5% | Apr 3, 2023 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shor... |
| CVE-2023-1766 | MEDIUM | 6.1 | 0.4% | Apr 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Pan... |
| CVE-2023-26529 | MEDIUM | 4.8 | 0.4% | Apr 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions. |
| CVE-2023-26112 | MEDIUM | 5.9 | 1.3% | Apr 3, 2023 | All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate fu... |
| CVE-2023-28684 | MEDIUM | 6.5 | 0.7% | Apr 2, 2023 | Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entit... |
| CVE-2023-28679 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a p... |
| CVE-2023-28678 | MEDIUM | 5.4 | 0.5% | Apr 2, 2023 | Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on th... |
| CVE-2023-28675 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect ... |
| CVE-2023-28673 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overal... |
| CVE-2023-28672 | MEDIUM | 6.5 | 0.5% | Apr 2, 2023 | Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test H... |
| CVE-2023-28671 | MEDIUM | 4.3 | 0.4% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allow... |
| CVE-2023-28670 | MEDIUM | 5.4 | 0.5% | Apr 2, 2023 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL ... |
| CVE-2023-28669 | MEDIUM | 5.4 | 0.6% | Apr 2, 2023 | Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cr... |
| CVE-2023-26283 | MEDIUM | 5.4 | 0.4% | Apr 2, 2023 | IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2023-1603 | MEDIUM | 6.5 | 0.6% | Apr 2, 2023 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior ver... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now