2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0878 | MEDIUM | 6.1 | 0.5% | Feb 17, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1. |
| CVE-2023-0821 | MEDIUM | 6.5 | 0.8% | Feb 16, 2023 | HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza s... |
| CVE-2023-22380 | MEDIUM | 6.5 | 0.7% | Feb 16, 2023 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when build... |
| CVE-2023-23784 | MEDIUM | 6.5 | 0.6% | Feb 16, 2023 | A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, Forti... |
| CVE-2023-23778 | MEDIUM | 6.5 | 0.6% | Feb 16, 2023 | A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions... |
| CVE-2023-22638 | MEDIUM | 5.4 | 0.5% | Feb 16, 2023 | Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below... |
| CVE-2023-0475 | MEDIUM | 6.5 | 0.5% | Feb 16, 2023 | HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0. |
| CVE-2023-24484 | MEDIUM | 5.5 | 0.3% | Feb 16, 2023 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. |
| CVE-2023-23936 | MEDIUM | 5.4 | 1.1% | Feb 16, 2023 | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library do... |
| CVE-2023-23752 | MEDIUM | 5.3 | 99.8% | Feb 16, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservic... |
| CVE-2023-23558 | MEDIUM | 6.3 | 0.3% | Feb 16, 2023 | In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sen... |
| CVE-2023-25153 | MEDIUM | 5.5 | 0.4% | Feb 16, 2023 | containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there wa... |
| CVE-2023-24499 | MEDIUM | 4.6 | 0.3% | Feb 15, 2023 | Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, ... |
| CVE-2023-23850 | MEDIUM | 4.3 | 0.5% | Feb 15, 2023 | A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read perm... |
| CVE-2023-23848 | MEDIUM | 4.3 | 0.5% | Feb 15, 2023 | Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permis... |
| CVE-2023-23467 | MEDIUM | 6.1 | 0.4% | Feb 15, 2023 | Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint. |
| CVE-2023-23458 | MEDIUM | 6.5 | 0.5% | Feb 15, 2023 | Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified r... |
| CVE-2023-22805 | MEDIUM | 4.3 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. T... |
| CVE-2023-25192 | MEDIUM | 5.3 | 0.5% | Feb 15, 2023 | AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat... |
| CVE-2023-25171 | MEDIUM | 5.9 | 0.9% | Feb 15, 2023 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e... |
| CVE-2023-25768 | MEDIUM | 6.5 | 0.6% | Feb 15, 2023 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa... |
| CVE-2023-25766 | MEDIUM | 4.3 | 0.5% | Feb 15, 2023 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa... |
| CVE-2023-25764 | MEDIUM | 5.4 | 0.6% | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or ... |
| CVE-2023-25763 | MEDIUM | 5.4 | 0.6% | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resu... |
| CVE-2023-25762 | MEDIUM | 5.4 | 81.4% | Feb 15, 2023 | Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now