2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32453LOW3.9 Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may po...
CVE-2023-28075MEDIUM6.3 Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical...
CVE-2023-4389HIGH7.1A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double...
CVE-2023-4387HIGH7.1A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethe...
CVE-2023-38737HIGH7.5IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by send...
CVE-2023-4385MEDIUM5.5A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linu...
CVE-2023-4204CRITICAL9.8NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses...
CVE-2023-39250MEDIUM5.5 Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6....
CVE-2023-2737MEDIUM5.5Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to ...
CVE-2023-40351MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Favorite View Plugin 5.v77a_37f62782d and earlier allows at...
CVE-2023-40350MEDIUM5.4Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the ...
CVE-2023-40349MEDIUM5.3Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthe...
CVE-2023-40348MEDIUM5.3The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the ...
CVE-2023-40347MEDIUM6.5Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for crede...
CVE-2023-40346MEDIUM5.4Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-si...
CVE-2023-40345MEDIUM6.5Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers...
CVE-2023-40344MEDIUM4.3A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to ...
CVE-2023-40343MEDIUM5.9Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an ...
CVE-2023-40342MEDIUM5.4Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins...
CVE-2023-40341HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to co...
CVE-2023-40340HIGH7.5Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in t...
CVE-2023-40339HIGH7.5Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) creden...
CVE-2023-40338MEDIUM4.3Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log...
CVE-2023-40337MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attac...
CVE-2023-40336HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attac...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now