2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-24724MEDIUM5.4A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Cons...
CVE-2023-1611MEDIUM6.3A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows a...
CVE-2023-28851MEDIUM5.4Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Start...
CVE-2023-28850MEDIUM5.4Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspect...
CVE-2023-28837MEDIUM4.9Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaust...
CVE-2023-28836MEDIUM5.4Wagtail is an open source content management system built on Django. Starting in version 1.5 and prior to versions 4.1.4...
CVE-2023-28834MEDIUM4.3Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, ...
CVE-2023-0977MEDIUM6.5 A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote use...
CVE-2023-1377MEDIUM6.1The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back ...
CVE-2023-1330MEDIUM6.5The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which c...
CVE-2023-0399MEDIUM5.4The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shor...
CVE-2023-1766MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Pan...
CVE-2023-26529MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions.
CVE-2023-26112MEDIUM5.9All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate fu...
CVE-2023-28684MEDIUM6.5Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entit...
CVE-2023-28679MEDIUM5.4Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a p...
CVE-2023-28678MEDIUM5.4Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on th...
CVE-2023-28675MEDIUM4.3A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect ...
CVE-2023-28673MEDIUM4.3A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overal...
CVE-2023-28672MEDIUM6.5Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test H...
CVE-2023-28671MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allow...
CVE-2023-28670MEDIUM5.4Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL ...
CVE-2023-28669MEDIUM5.4Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cr...
CVE-2023-26283MEDIUM5.4IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2023-1603MEDIUM6.5 Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior ver...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now