2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41938 | MEDIUM | 6.5 | 0.3% | Sep 6, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disab... |
| CVE-2023-41937 | HIGH | 7.5 | 0.6% | Sep 6, 2023 | Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhoo... |
| CVE-2023-41936 | HIGH | 7.5 | 0.7% | Sep 6, 2023 | Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provi... |
| CVE-2023-41935 | HIGH | 7.5 | 0.7% | Sep 6, 2023 | Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time compari... |
| CVE-2023-41934 | MEDIUM | 5.3 | 0.5% | Sep 6, 2023 | Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with aste... |
| CVE-2023-41933 | HIGH | 8.8 | 0.8% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XM... |
| CVE-2023-41932 | MEDIUM | 6.5 | 0.6% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters ... |
| CVE-2023-41931 | MEDIUM | 5.4 | 0.4% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timest... |
| CVE-2023-41930 | MEDIUM | 4.3 | 0.8% | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter wh... |
| CVE-2023-41150 | MEDIUM | 5.4 | 0.3% | Sep 6, 2023 | F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is explo... |
| CVE-2023-41149 | CRITICAL | 9.8 | 1.3% | Sep 6, 2023 | F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploit... |
| CVE-2023-39264 | MEDIUM | 4.3 | 0.8% | Sep 6, 2023 | By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoint... |
| CVE-2023-36388 | MEDIUM | 5.4 | 0.8% | Sep 6, 2023 | Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to tes... |
| CVE-2023-36387 | MEDIUM | 5.4 | 0.8% | Sep 6, 2023 | An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authe... |
| CVE-2023-27526 | MEDIUM | 4.3 | 0.9% | Sep 6, 2023 | A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up... |
| CVE-2023-27523 | MEDIUM | 4.3 | 0.7% | Sep 6, 2023 | Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an ... |
| CVE-2023-4589 | HIGH | 7.2 | 0.3% | Sep 6, 2023 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An a... |
| CVE-2023-4588 | MEDIUM | 4.9 | 0.3% | Sep 6, 2023 | File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation o... |
| CVE-2023-40531 | HIGH | 8 | 0.4% | Sep 6, 2023 | Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authentic... |
| CVE-2023-40357 | HIGH | 8 | 0.4% | Sep 6, 2023 | Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro... |
| CVE-2023-40193 | HIGH | 8 | 0.4% | Sep 6, 2023 | Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacke... |
| CVE-2023-39935 | HIGH | 8 | 0.4% | Sep 6, 2023 | Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to... |
| CVE-2023-39224 | HIGH | 8 | 0.4% | Sep 6, 2023 | Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjac... |
| CVE-2023-38588 | HIGH | 8 | 0.4% | Sep 6, 2023 | Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to... |
| CVE-2023-38568 | HIGH | 8.8 | 0.4% | Sep 6, 2023 | Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to e... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now