2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33004 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission ... |
| CVE-2023-33003 | MEDIUM | 4.3 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to res... |
| CVE-2023-33002 | MEDIUM | 5.4 | 2.4% | May 16, 2023 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stor... |
| CVE-2023-33001 | HIGH | 7.5 | 0.6% | May 16, 2023 | Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) cred... |
| CVE-2023-33000 | HIGH | 7.5 | 0.6% | May 16, 2023 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the ... |
| CVE-2023-32999 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission ... |
| CVE-2023-32998 | HIGH | 8.8 | 0.5% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to con... |
| CVE-2023-32997 | HIGH | 8.8 | 0.8% | May 16, 2023 | Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login. |
| CVE-2023-32996 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Re... |
| CVE-2023-32995 | HIGH | 8.8 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows at... |
| CVE-2023-32994 | LOW | 3.7 | 0.2% | May 16, 2023 | Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for co... |
| CVE-2023-32993 | MEDIUM | 4.8 | 0.2% | May 16, 2023 | Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr... |
| CVE-2023-32992 | HIGH | 8.8 | 0.8% | May 16, 2023 | Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read... |
| CVE-2023-32991 | HIGH | 8.8 | 0.7% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows at... |
| CVE-2023-32990 | MEDIUM | 6.5 | 0.6% | May 16, 2023 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal... |
| CVE-2023-2740 | MEDIUM | 6.1 | 0.5% | May 16, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Guest Management System 1.0. Affe... |
| CVE-2023-32989 | HIGH | 8.8 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allow... |
| CVE-2023-32988 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal... |
| CVE-2023-32987 | HIGH | 8.8 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attacker... |
| CVE-2023-32986 | HIGH | 8.8 | 63.1% | May 16, 2023 | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file na... |
| CVE-2023-32985 | MEDIUM | 4.3 | 72.4% | May 16, 2023 | Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validati... |
| CVE-2023-32984 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG r... |
| CVE-2023-32983 | MEDIUM | 5.3 | 0.4% | May 16, 2023 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form,... |
| CVE-2023-32982 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the ... |
| CVE-2023-32981 | HIGH | 8.8 | 1.0% | May 16, 2023 | An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now