2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-20135HIGH7A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execu...
CVE-2023-4801HIGH7.5An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used ...
CVE-2023-39915HIGH7.5NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects....
CVE-2023-39914HIGH7.5NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than...
CVE-2023-40717HIGH7.8A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who man...
CVE-2023-36642HIGH7.8An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface ...
CVE-2023-36634HIGH8.8An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr...
CVE-2023-34984HIGH8.8A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6...
CVE-2023-41081HIGH7.5Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances,...
CVE-2023-26369HIGH7.8Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affect...
CVE-2023-4916HIGH8.8The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2023-4213HIGH8.8The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions u...
CVE-2023-4153HIGH8.8The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to ...
CVE-2023-4928HIGH7.2 SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4921HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local priv...
CVE-2023-4918HIGH8.8A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself throu...
CVE-2023-3712HIGH7.8Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page mod...
CVE-2023-3711HIGH8.8Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Fal...
CVE-2023-39208HIGH7.5Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c...
CVE-2023-21521HIGH7.2 An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could...
CVE-2023-38163HIGH7.8Windows Defender Attack Surface Reduction Security Feature Bypass
CVE-2023-38162HIGH7.5DHCP Server Service Denial of Service Vulnerability
CVE-2023-38161HIGH7.8Windows GDI Elevation of Privilege Vulnerability
CVE-2023-38156HIGH7.2Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
CVE-2023-38155HIGH8.1Azure DevOps Server Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now