2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24494 | MEDIUM | 5.4 | 0.7% | Jan 26, 2023 | A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input... |
| CVE-2023-24493 | MEDIUM | 5.7 | 0.7% | Jan 26, 2023 | A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returnin... |
| CVE-2023-24459 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission t... |
| CVE-2023-24457 | MEDIUM | 6.5 | 1.0% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows att... |
| CVE-2023-24455 | MEDIUM | 4.3 | 1.2% | Jan 26, 2023 | Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation... |
| CVE-2023-24454 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global con... |
| CVE-2023-24453 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to c... |
| CVE-2023-24451 | MEDIUM | 4.3 | 0.6% | Jan 26, 2023 | A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read p... |
| CVE-2023-24450 | MEDIUM | 6.5 | 0.6% | Jan 26, 2023 | Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controlle... |
| CVE-2023-24449 | MEDIUM | 4.3 | 1.2% | Jan 26, 2023 | Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form v... |
| CVE-2023-24448 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permis... |
| CVE-2023-24445 | MEDIUM | 6.1 | 0.7% | Jan 26, 2023 | Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to ... |
| CVE-2023-24442 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar acce... |
| CVE-2023-24440 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of ... |
| CVE-2023-24439 | MEDIUM | 5.5 | 0.2% | Jan 26, 2023 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global c... |
| CVE-2023-24438 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with... |
| CVE-2023-24436 | MEDIUM | 4.3 | 0.7% | Jan 26, 2023 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal... |
| CVE-2023-24435 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal... |
| CVE-2023-24433 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permis... |
| CVE-2023-24431 | MEDIUM | 4.3 | 0.6% | Jan 26, 2023 | A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read perm... |
| CVE-2023-24428 | MEDIUM | 5.7 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to... |
| CVE-2023-24425 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for ... |
| CVE-2023-24423 | MEDIUM | 6.5 | 0.5% | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers t... |
| CVE-2023-23951 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application |
| CVE-2023-23950 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now