2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23842 | HIGH | 7.2 | 3.3% | Jul 26, 2023 | The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerabilit... |
| CVE-2023-39156 | MEDIUM | 5.3 | 0.3% | Jul 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete p... |
| CVE-2023-39155 | MEDIUM | 5.3 | 0.4% | Jul 26, 2023 | Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a... |
| CVE-2023-39154 | MEDIUM | 6.5 | 0.5% | Jul 26, 2023 | Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with ... |
| CVE-2023-39153 | MEDIUM | 5.4 | 0.6% | Jul 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows atta... |
| CVE-2023-39152 | MEDIUM | 6.5 | 0.6% | Jul 26, 2023 | Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.... |
| CVE-2023-39151 | MEDIUM | 5.4 | 0.9% | Jul 26, 2023 | Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transfor... |
| CVE-2023-33225 | HIGH | 7.2 | 3.3% | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-33224 | HIGH | 7.2 | 2.8% | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users w... |
| CVE-2023-26911 | HIGH | 7.8 | 0.2% | Jul 26, 2023 | ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which all... |
| CVE-2023-26859 | CRITICAL | 9.8 | 0.6% | Jul 26, 2023 | SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privilege... |
| CVE-2023-23844 | HIGH | 7.2 | 3.0% | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-23843 | HIGH | 7.2 | 2.6% | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-39261 | HIGH | 7.8 | 0.3% | Jul 26, 2023 | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions |
| CVE-2023-37049 | MEDIUM | 6.5 | 0.6% | Jul 26, 2023 | emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. |
| CVE-2023-38673 | CRITICAL | 9.8 | 2.0% | Jul 26, 2023 | PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands o... |
| CVE-2023-38672 | HIGH | 7.5 | 0.6% | Jul 26, 2023 | FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service. |
| CVE-2023-38671 | CRITICAL | 9.8 | 0.6% | Jul 26, 2023 | Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, informatio... |
| CVE-2023-38670 | HIGH | 7.5 | 0.6% | Jul 26, 2023 | Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of ser... |
| CVE-2023-28130 | HIGH | 7.2 | 21.4% | Jul 26, 2023 | Local user may lead to privilege escalation using Gaia Portal hostnames page. |
| CVE-2023-38669 | CRITICAL | 9.8 | 0.7% | Jul 26, 2023 | Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition. |
| CVE-2023-38647 | CRITICAL | 9.8 | 1.5% | Jul 26, 2023 | An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and th... |
| CVE-2023-38555 | HIGH | 8.8 | 0.3% | Jul 26, 2023 | Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent una... |
| CVE-2023-38433 | HIGH | 7.5 | 3.0% | Jul 26, 2023 | Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticat... |
| CVE-2023-32468 | MEDIUM | 4.9 | 0.4% | Jul 26, 2023 | Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now