2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33004MEDIUM4.3A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission ...
CVE-2023-33003MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to res...
CVE-2023-33002MEDIUM5.4Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stor...
CVE-2023-33001HIGH7.5Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) cred...
CVE-2023-33000HIGH7.5Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the ...
CVE-2023-32999MEDIUM4.3A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission ...
CVE-2023-32998HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to con...
CVE-2023-32997HIGH8.8Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.
CVE-2023-32996MEDIUM4.3A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Re...
CVE-2023-32995HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows at...
CVE-2023-32994LOW3.7Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for co...
CVE-2023-32993MEDIUM4.8Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr...
CVE-2023-32992HIGH8.8Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read...
CVE-2023-32991HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows at...
CVE-2023-32990MEDIUM6.5A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal...
CVE-2023-2740MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Guest Management System 1.0. Affe...
CVE-2023-32989HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allow...
CVE-2023-32988MEDIUM4.3A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal...
CVE-2023-32987HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attacker...
CVE-2023-32986HIGH8.8Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file na...
CVE-2023-32985MEDIUM4.3Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validati...
CVE-2023-32984MEDIUM5.4Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG r...
CVE-2023-32983MEDIUM5.3Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form,...
CVE-2023-32982MEDIUM4.3Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the ...
CVE-2023-32981HIGH8.8An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now