2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20238 | CRITICAL | 9.8 | 15.3% | Sep 6, 2023 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco B... |
| CVE-2023-0925 | CRITICAL | 9.8 | 0.6% | Sep 6, 2023 | Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry ... |
| CVE-2023-4498 | MEDIUM | 5.3 | 0.4% | Sep 6, 2023 | Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to aut... |
| CVE-2023-20250 | HIGH | 7.2 | 0.8% | Sep 6, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers ... |
| CVE-2023-4623 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be e... |
| CVE-2023-4622 | HIGH | 7 | 0.5% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escal... |
| CVE-2023-4621 | — | — | — | Sep 6, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ... |
| CVE-2023-4244 | HIGH | 7 | 0.2% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-4208 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv... |
| CVE-2023-4207 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi... |
| CVE-2023-4206 | HIGH | 7.8 | 0.6% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local pr... |
| CVE-2023-4015 | HIGH | 7.8 | 0.3% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-3777 | HIGH | 7.8 | 0.4% | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-39265 | MEDIUM | 6.5 | 83.7% | Sep 6, 2023 | Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati... |
| CVE-2023-37941 | MEDIUM | 6.6 | 29.2% | Sep 6, 2023 | If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py... |
| CVE-2023-32672 | MEDIUM | 4.3 | 0.7% | Sep 6, 2023 | An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all... |
| CVE-2023-41947 | MEDIUM | 4.3 | 0.4% | Sep 6, 2023 | A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permissio... |
| CVE-2023-41946 | LOW | 3.5 | 0.3% | Sep 6, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to c... |
| CVE-2023-41945 | HIGH | 8.8 | 0.6% | Sep 6, 2023 | Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in u... |
| CVE-2023-41944 | MEDIUM | 6.1 | 0.4% | Sep 6, 2023 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form valid... |
| CVE-2023-41943 | MEDIUM | 6.5 | 0.5% | Sep 6, 2023 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi... |
| CVE-2023-41942 | MEDIUM | 4.3 | 0.3% | Sep 6, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows att... |
| CVE-2023-41941 | MEDIUM | 4.3 | 0.4% | Sep 6, 2023 | A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Rea... |
| CVE-2023-41940 | MEDIUM | 5.4 | 0.5% | Sep 6, 2023 | Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) v... |
| CVE-2023-41939 | HIGH | 8.8 | 0.6% | Sep 6, 2023 | Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentia... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now