2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27742CRITICAL9.8IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
CVE-2023-30510MEDIUM4.3A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated use...
CVE-2023-30509MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-30508MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-30507MEDIUM6.5Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. ...
CVE-2023-30506HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-30505HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-30504HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-30503HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-30502HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-30501HIGH8.8Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users t...
CVE-2023-2726HIGH8.8Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinc...
CVE-2023-2725HIGH8.8Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to instal...
CVE-2023-2724HIGH8.8Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-2723HIGH8.8Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the re...
CVE-2023-2722HIGH8.8Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potential...
CVE-2023-2721HIGH8.8Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit h...
CVE-2023-2631MEDIUM4.3A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to ...
CVE-2023-2195LOW3.5A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers to connec...
CVE-2023-2633MEDIUM4.3Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, incr...
CVE-2023-2632MEDIUM4.3Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenki...
CVE-2023-2196MEDIUM4.3A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to che...
CVE-2023-33007MEDIUM5.4Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cr...
CVE-2023-33006MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick...
CVE-2023-33005MEDIUM5.4Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now