2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32980 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another use... |
| CVE-2023-32979 | MEDIUM | 4.3 | 0.5% | May 16, 2023 | Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing at... |
| CVE-2023-32978 | MEDIUM | 4.3 | 0.3% | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-spec... |
| CVE-2023-32977 | MEDIUM | 5.4 | 0.6% | May 16, 2023 | Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, r... |
| CVE-2023-31890 | CRITICAL | 9.8 | 1.0% | May 16, 2023 | An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXML... |
| CVE-2023-2739 | MEDIUM | 6.1 | 0.4% | May 16, 2023 | A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affe... |
| CVE-2023-28076 | HIGH | 7.5 | 0.4% | May 16, 2023 | CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthentica... |
| CVE-2023-31857 | CRITICAL | 9.8 | 1.5% | May 16, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code executio... |
| CVE-2023-31856 | CRITICAL | 9.8 | 2.9% | May 16, 2023 | A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.759... |
| CVE-2023-31587 | CRITICAL | 9.8 | 2.0% | May 16, 2023 | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac paramete... |
| CVE-2023-31519 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login... |
| CVE-2023-2738 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the... |
| CVE-2023-29439 | MEDIUM | 6.1 | 1.7% | May 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. |
| CVE-2023-31576 | HIGH | 8.8 | 1.1% | May 16, 2023 | An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted... |
| CVE-2023-31572 | HIGH | 8.8 | 0.8% | May 16, 2023 | An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privilege... |
| CVE-2023-2730 | MEDIUM | 5.4 | 0.5% | May 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. |
| CVE-2023-23720 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin... |
| CVE-2023-23709 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1 versions. |
| CVE-2023-23703 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1... |
| CVE-2023-23657 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe L... |
| CVE-2023-23641 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPmanage Uji Popup plugin <= 1.4.3 versions. |
| CVE-2023-2548 | HIGH | 7.2 | 0.7% | May 16, 2023 | The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and inc... |
| CVE-2023-2499 | CRITICAL | 9.8 | 1.3% | May 16, 2023 | The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.... |
| CVE-2023-23727 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Formilla Live Chat by Formilla plugin <= 1.3 versions. |
| CVE-2023-23676 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now