2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40930MEDIUM6.8An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mount...
CVE-2023-39052MEDIUM6.5An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted m...
CVE-2023-39045MEDIUM6.5An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send cra...
CVE-2023-38718MEDIUM5.3IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, ...
CVE-2023-37410HIGH7.8IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM...
CVE-2023-43377MEDIUM5.4A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers...
CVE-2023-43376MEDIUM5.4A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute a...
CVE-2023-43375CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the an...
CVE-2023-43374CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid...
CVE-2023-43373CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/...
CVE-2023-43371CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/cr...
CVE-2023-40368MEDIUM4.4IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the admi...
CVE-2023-39041MEDIUM6.5An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted mess...
CVE-2023-40619CRITICAL9.8phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution...
CVE-2023-40618MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visu...
CVE-2023-39044MEDIUM6.5An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted...
CVE-2023-20597MEDIUM5.5Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc...
CVE-2023-20594MEDIUM4.4Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via loc...
CVE-2023-43502MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta...
CVE-2023-43501MEDIUM6.5A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read...
CVE-2023-43500HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta...
CVE-2023-43499MEDIUM5.4Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in ...
CVE-2023-43498HIGH8.1In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates tem...
CVE-2023-43497HIGH8.1In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates t...
CVE-2023-43496HIGH8.8Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now