2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27742 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login. |
| CVE-2023-30510 | MEDIUM | 4.3 | 0.6% | May 16, 2023 | A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated use... |
| CVE-2023-30509 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-30508 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-30507 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ... |
| CVE-2023-30506 | HIGH | 8.8 | 1.1% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-30505 | HIGH | 8.8 | 1.0% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-30504 | HIGH | 8.8 | 1.0% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-30503 | HIGH | 8.8 | 1.0% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-30502 | HIGH | 8.8 | 1.1% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-30501 | HIGH | 8.8 | 1.0% | May 16, 2023 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t... |
| CVE-2023-2726 | HIGH | 8.8 | 0.7% | May 16, 2023 | Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinc... |
| CVE-2023-2725 | HIGH | 8.8 | 24.7% | May 16, 2023 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to instal... |
| CVE-2023-2724 | HIGH | 8.8 | 29.1% | May 16, 2023 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-2723 | HIGH | 8.8 | 15.4% | May 16, 2023 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the re... |
| CVE-2023-2722 | HIGH | 8.8 | 0.9% | May 16, 2023 | Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potential... |
| CVE-2023-2721 | HIGH | 8.8 | 0.9% | May 16, 2023 | Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit h... |
| CVE-2023-2631 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to ... |
| CVE-2023-2195 | LOW | 3.5 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers to connec... |
| CVE-2023-2633 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, incr... |
| CVE-2023-2632 | MEDIUM | 4.3 | 0.6% | May 16, 2023 | Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenki... |
| CVE-2023-2196 | MEDIUM | 4.3 | 1.0% | May 16, 2023 | A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to che... |
| CVE-2023-33007 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cr... |
| CVE-2023-33006 | MEDIUM | 5.4 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick... |
| CVE-2023-33005 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now