2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20135 | HIGH | 7 | 0.1% | Sep 13, 2023 | A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execu... |
| CVE-2023-4801 | HIGH | 7.5 | 0.2% | Sep 13, 2023 | An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used ... |
| CVE-2023-39915 | HIGH | 7.5 | 0.5% | Sep 13, 2023 | NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects.... |
| CVE-2023-39914 | HIGH | 7.5 | 0.6% | Sep 13, 2023 | NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than... |
| CVE-2023-40717 | HIGH | 7.8 | 0.2% | Sep 13, 2023 | A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who man... |
| CVE-2023-36642 | HIGH | 7.8 | 0.2% | Sep 13, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface ... |
| CVE-2023-36634 | HIGH | 8.8 | 0.5% | Sep 13, 2023 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr... |
| CVE-2023-34984 | HIGH | 8.8 | 0.7% | Sep 13, 2023 | A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6... |
| CVE-2023-41081 | HIGH | 7.5 | 1.3% | Sep 13, 2023 | Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances,... |
| CVE-2023-26369 | HIGH | 7.8 | 7.0% | Sep 13, 2023 | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affect... |
| CVE-2023-4916 | HIGH | 8.8 | 0.3% | Sep 13, 2023 | The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2023-4213 | HIGH | 8.8 | 0.6% | Sep 13, 2023 | The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions u... |
| CVE-2023-4153 | HIGH | 8.8 | 0.7% | Sep 13, 2023 | The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to ... |
| CVE-2023-4928 | HIGH | 7.2 | 0.7% | Sep 13, 2023 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4921 | HIGH | 7.8 | 0.4% | Sep 12, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local priv... |
| CVE-2023-4918 | HIGH | 8.8 | 0.5% | Sep 12, 2023 | A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself throu... |
| CVE-2023-3712 | HIGH | 7.8 | 0.5% | Sep 12, 2023 | Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page mod... |
| CVE-2023-3711 | HIGH | 8.8 | 0.9% | Sep 12, 2023 | Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Fal... |
| CVE-2023-39208 | HIGH | 7.5 | 0.5% | Sep 12, 2023 | Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c... |
| CVE-2023-21521 | HIGH | 7.2 | 0.5% | Sep 12, 2023 | An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could... |
| CVE-2023-38163 | HIGH | 7.8 | 0.6% | Sep 12, 2023 | Windows Defender Attack Surface Reduction Security Feature Bypass |
| CVE-2023-38162 | HIGH | 7.5 | 10.3% | Sep 12, 2023 | DHCP Server Service Denial of Service Vulnerability |
| CVE-2023-38161 | HIGH | 7.8 | 0.8% | Sep 12, 2023 | Windows GDI Elevation of Privilege Vulnerability |
| CVE-2023-38156 | HIGH | 7.2 | 1.9% | Sep 12, 2023 | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability |
| CVE-2023-38155 | HIGH | 8.1 | 1.3% | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now