2023 CVE Vulnerabilities
31,399 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5721 | MEDIUM | 4.3 | 0.8% | Oct 25, 2023 | It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to ... |
| CVE-2023-5717 | HIGH | 7.8 | 0.9% | Oct 25, 2023 | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be e... |
| CVE-2023-5671 | HIGH | 7.8 | 0.2% | Oct 25, 2023 | HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software ... |
| CVE-2023-5568 | MEDIUM | 6.5 | 1.6% | Oct 25, 2023 | A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit th... |
| CVE-2023-5472 | HIGH | 8.8 | 1.2% | Oct 25, 2023 | Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit hea... |
| CVE-2023-5363 | HIGH | 7.5 | 3.3% | Oct 25, 2023 | Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead... |
| CVE-2023-5311 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2023-5127 | MEDIUM | 5.4 | 0.6% | Oct 25, 2023 | The WP Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, ... |
| CVE-2023-5126 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | The Delete Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'plugin_delete_me' shortcode in vers... |
| CVE-2023-5110 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' s... |
| CVE-2023-5085 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | The Advanced Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'advMenu' shortcode in ve... |
| CVE-2023-4693 | MEDIUM | 4.6 | 0.5% | Oct 25, 2023 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attack... |
| CVE-2023-4692 | HIGH | 7.8 | 0.5% | Oct 25, 2023 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a s... |
| CVE-2023-4608 | HIGH | 7.2 | 0.3% | Oct 25, 2023 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted AP... |
| CVE-2023-4607 | HIGH | 8.8 | 0.4% | Oct 25, 2023 | An authenticated XCC user can change permissions for any user through a crafted API command. |
| CVE-2023-4606 | HIGH | 8.1 | 0.5% | Oct 25, 2023 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command... |
| CVE-2023-46660 | MEDIUM | 5.3 | 0.5% | Oct 25, 2023 | Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided an... |
| CVE-2023-46659 | MEDIUM | 5.4 | 0.5% | Oct 25, 2023 | Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a sto... |
| CVE-2023-46658 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whet... |
| CVE-2023-46657 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided a... |
| CVE-2023-46656 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when chec... |
| CVE-2023-46655 | MEDIUM | 6.5 | 1.2% | Oct 25, 2023 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which a... |
| CVE-2023-46654 | HIGH | 8.1 | 1.4% | Oct 25, 2023 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory dur... |
| CVE-2023-46653 | MEDIUM | 6.5 | 0.4% | Oct 25, 2023 | Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, pot... |
| CVE-2023-46652 | MEDIUM | 4.3 | 0.4% | Oct 25, 2023 | A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now