2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23842HIGH7.2The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerabilit...
CVE-2023-39156MEDIUM5.3A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete p...
CVE-2023-39155MEDIUM5.3Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a...
CVE-2023-39154MEDIUM6.5Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with ...
CVE-2023-39153MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows atta...
CVE-2023-39152MEDIUM6.5Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i....
CVE-2023-39151MEDIUM5.4Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transfor...
CVE-2023-33225HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-33224HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users w...
CVE-2023-26911HIGH7.8ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which all...
CVE-2023-26859CRITICAL9.8SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privilege...
CVE-2023-23844HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-23843HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-39261HIGH7.8In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
CVE-2023-37049MEDIUM6.5emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
CVE-2023-38673CRITICAL9.8PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands o...
CVE-2023-38672HIGH7.5FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-38671CRITICAL9.8Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, informatio...
CVE-2023-38670HIGH7.5Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of ser...
CVE-2023-28130HIGH7.2Local user may lead to privilege escalation using Gaia Portal hostnames page.
CVE-2023-38669CRITICAL9.8Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.
CVE-2023-38647CRITICAL9.8An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and th...
CVE-2023-38555HIGH8.8Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent una...
CVE-2023-38433HIGH7.5Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticat...
CVE-2023-32468MEDIUM4.9 Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now