2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41938MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disab...
CVE-2023-41937HIGH7.5Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhoo...
CVE-2023-41936HIGH7.5Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provi...
CVE-2023-41935HIGH7.5Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time compari...
CVE-2023-41934MEDIUM5.3Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with aste...
CVE-2023-41933HIGH8.8Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XM...
CVE-2023-41932MEDIUM6.5Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters ...
CVE-2023-41931MEDIUM5.4Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timest...
CVE-2023-41930MEDIUM4.3Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter wh...
CVE-2023-41150MEDIUM5.4F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is explo...
CVE-2023-41149CRITICAL9.8F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploit...
CVE-2023-39264MEDIUM4.3By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoint...
CVE-2023-36388MEDIUM5.4Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to tes...
CVE-2023-36387MEDIUM5.4An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authe...
CVE-2023-27526MEDIUM4.3A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up...
CVE-2023-27523MEDIUM4.3Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an ...
CVE-2023-4589HIGH7.2Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An a...
CVE-2023-4588MEDIUM4.9File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation o...
CVE-2023-40531HIGH8Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authentic...
CVE-2023-40357HIGH8Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro...
CVE-2023-40193HIGH8Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacke...
CVE-2023-39935HIGH8Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to...
CVE-2023-39224HIGH8Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjac...
CVE-2023-38588HIGH8Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to...
CVE-2023-38568HIGH8.8Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to e...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now