2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0878MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.
CVE-2023-0821MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza s...
CVE-2023-22380MEDIUM6.5A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when build...
CVE-2023-23784MEDIUM6.5A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, Forti...
CVE-2023-23778MEDIUM6.5A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions...
CVE-2023-22638MEDIUM5.4Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below...
CVE-2023-0475MEDIUM6.5HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
CVE-2023-24484MEDIUM5.5A malicious user can cause log files to be written to a directory that they do not have permission to write to.
CVE-2023-23936MEDIUM5.4Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library do...
CVE-2023-23752MEDIUM5.3An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservic...
CVE-2023-23558MEDIUM6.3In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sen...
CVE-2023-25153MEDIUM5.5containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there wa...
CVE-2023-24499MEDIUM4.6Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, ...
CVE-2023-23850MEDIUM4.3A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read perm...
CVE-2023-23848MEDIUM4.3Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permis...
CVE-2023-23467MEDIUM6.1Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
CVE-2023-23458MEDIUM6.5Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified r...
CVE-2023-22805MEDIUM4.3LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. T...
CVE-2023-25192MEDIUM5.3AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat...
CVE-2023-25171MEDIUM5.9Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e...
CVE-2023-25768MEDIUM6.5A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa...
CVE-2023-25766MEDIUM4.3A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa...
CVE-2023-25764MEDIUM5.4Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or ...
CVE-2023-25763MEDIUM5.4Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resu...
CVE-2023-25762MEDIUM5.4Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now