2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32453 | LOW | 3.9 | 0.2% | Aug 16, 2023 | Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may po... |
| CVE-2023-28075 | MEDIUM | 6.3 | 0.2% | Aug 16, 2023 | Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical... |
| CVE-2023-4389 | HIGH | 7.1 | 0.3% | Aug 16, 2023 | A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double... |
| CVE-2023-4387 | HIGH | 7.1 | 0.2% | Aug 16, 2023 | A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethe... |
| CVE-2023-38737 | HIGH | 7.5 | 0.8% | Aug 16, 2023 | IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by send... |
| CVE-2023-4385 | MEDIUM | 5.5 | 0.2% | Aug 16, 2023 | A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linu... |
| CVE-2023-4204 | CRITICAL | 9.8 | 0.3% | Aug 16, 2023 | NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses... |
| CVE-2023-39250 | MEDIUM | 5.5 | 0.1% | Aug 16, 2023 | Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.... |
| CVE-2023-2737 | MEDIUM | 5.5 | 0.1% | Aug 16, 2023 | Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to ... |
| CVE-2023-40351 | MEDIUM | 4.3 | 0.3% | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Favorite View Plugin 5.v77a_37f62782d and earlier allows at... |
| CVE-2023-40350 | MEDIUM | 5.4 | 0.5% | Aug 16, 2023 | Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the ... |
| CVE-2023-40349 | MEDIUM | 5.3 | 0.6% | Aug 16, 2023 | Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthe... |
| CVE-2023-40348 | MEDIUM | 5.3 | 0.5% | Aug 16, 2023 | The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the ... |
| CVE-2023-40347 | MEDIUM | 6.5 | 0.6% | Aug 16, 2023 | Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for crede... |
| CVE-2023-40346 | MEDIUM | 5.4 | 0.4% | Aug 16, 2023 | Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-si... |
| CVE-2023-40345 | MEDIUM | 6.5 | 0.8% | Aug 16, 2023 | Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers... |
| CVE-2023-40344 | MEDIUM | 4.3 | 0.5% | Aug 16, 2023 | A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to ... |
| CVE-2023-40343 | MEDIUM | 5.9 | 0.5% | Aug 16, 2023 | Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an ... |
| CVE-2023-40342 | MEDIUM | 5.4 | 0.5% | Aug 16, 2023 | Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins... |
| CVE-2023-40341 | HIGH | 8.8 | 0.5% | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to co... |
| CVE-2023-40340 | HIGH | 7.5 | 0.5% | Aug 16, 2023 | Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in t... |
| CVE-2023-40339 | HIGH | 7.5 | 0.7% | Aug 16, 2023 | Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) creden... |
| CVE-2023-40338 | MEDIUM | 4.3 | 0.5% | Aug 16, 2023 | Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log... |
| CVE-2023-40337 | MEDIUM | 4.3 | 0.3% | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attac... |
| CVE-2023-40336 | HIGH | 8.8 | 0.4% | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attac... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now