2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20238CRITICAL9.8A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco B...
CVE-2023-0925CRITICAL9.8Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry ...
CVE-2023-4498MEDIUM5.3Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to aut...
CVE-2023-20250HIGH7.2A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers ...
CVE-2023-4623HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be e...
CVE-2023-4622HIGH7A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escal...
CVE-2023-4621Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ...
CVE-2023-4244HIGH7A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-4208HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv...
CVE-2023-4207HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi...
CVE-2023-4206HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local pr...
CVE-2023-4015HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-3777HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-39265MEDIUM6.5Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati...
CVE-2023-37941MEDIUM6.6If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py...
CVE-2023-32672MEDIUM4.3An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all...
CVE-2023-41947MEDIUM4.3A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permissio...
CVE-2023-41946LOW3.5A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to c...
CVE-2023-41945HIGH8.8Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in u...
CVE-2023-41944MEDIUM6.1Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form valid...
CVE-2023-41943MEDIUM6.5Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi...
CVE-2023-41942MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows att...
CVE-2023-41941MEDIUM4.3A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Rea...
CVE-2023-41940MEDIUM5.4Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) v...
CVE-2023-41939HIGH8.8Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentia...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now