2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40930 | MEDIUM | 6.8 | 1.2% | Sep 20, 2023 | An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mount... |
| CVE-2023-39052 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted m... |
| CVE-2023-39045 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send cra... |
| CVE-2023-38718 | MEDIUM | 5.3 | 0.4% | Sep 20, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, ... |
| CVE-2023-37410 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM... |
| CVE-2023-43377 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers... |
| CVE-2023-43376 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute a... |
| CVE-2023-43375 | CRITICAL | 9.8 | 0.6% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the an... |
| CVE-2023-43374 | CRITICAL | 9.8 | 3.3% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid... |
| CVE-2023-43373 | CRITICAL | 9.8 | 3.8% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/... |
| CVE-2023-43371 | CRITICAL | 9.8 | 0.9% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/cr... |
| CVE-2023-40368 | MEDIUM | 4.4 | 0.2% | Sep 20, 2023 | IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the admi... |
| CVE-2023-39041 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted mess... |
| CVE-2023-40619 | CRITICAL | 9.8 | 1.1% | Sep 20, 2023 | phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution... |
| CVE-2023-40618 | MEDIUM | 6.1 | 0.5% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visu... |
| CVE-2023-39044 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted... |
| CVE-2023-20597 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc... |
| CVE-2023-20594 | MEDIUM | 4.4 | 0.2% | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc... |
| CVE-2023-43502 | MEDIUM | 4.3 | 0.3% | Sep 20, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta... |
| CVE-2023-43501 | MEDIUM | 6.5 | 0.5% | Sep 20, 2023 | A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read... |
| CVE-2023-43500 | HIGH | 8.8 | 0.4% | Sep 20, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta... |
| CVE-2023-43499 | MEDIUM | 5.4 | 0.5% | Sep 20, 2023 | Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in ... |
| CVE-2023-43498 | HIGH | 8.1 | 0.8% | Sep 20, 2023 | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates tem... |
| CVE-2023-43497 | HIGH | 8.1 | 0.8% | Sep 20, 2023 | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates t... |
| CVE-2023-43496 | HIGH | 8.8 | 0.9% | Sep 20, 2023 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the d... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now