2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-22639HIGH7.8A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS ver...
CVE-2023-22633HIGH7.5An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and...
CVE-2023-2729HIGH7.5Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM)...
CVE-2023-0142HIGH8.1Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) ...
CVE-2023-33991HIGH8.2SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not s...
CVE-2023-26298HIGH8.8Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation...
CVE-2023-26297HIGH8.8Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation...
CVE-2023-26296HIGH8.8Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation...
CVE-2023-26294HIGH7.8Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation...
CVE-2023-32221HIGH7.8EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privileg...
CVE-2023-32219HIGH7.5A Mazda model (2015-2016) can be unlocked via an unspecified method.
CVE-2023-34942HIGH7.5Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NO...
CVE-2023-34940HIGH7.5Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NO...
CVE-2023-28478HIGH8.8TP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.
CVE-2023-1899HIGH7.5Atlas Copco Power Focus 6000 web server is not a secure connection by default, which could allow an attacker to gain sen...
CVE-2023-1898HIGH7.5Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID ...
CVE-2023-1897HIGH7.5Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s brows...
CVE-2023-34343HIGH8.8AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar...
CVE-2023-34336HIGH8.8AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer ...
CVE-2023-34334HIGH8.8AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar...
CVE-2023-34341HIGH8.8AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write ...
CVE-2023-34105HIGH7.5SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5...
CVE-2023-30198HIGH7.5Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download...
CVE-2023-35053HIGH7.5In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
CVE-2023-34468HIGH8.8The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now