2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46713 | MEDIUM | 5.3 | 0.5% | Dec 13, 2023 | An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.... |
| CVE-2023-46675 | MEDIUM | 6.5 | 0.6% | Dec 13, 2023 | An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error... |
| CVE-2023-46671 | MEDIUM | 6.5 | 0.7% | Dec 13, 2023 | An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error... |
| CVE-2023-45587 | MEDIUM | 5.4 | 0.4% | Dec 13, 2023 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2023-41844 | MEDIUM | 5.4 | 0.4% | Dec 13, 2023 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa... |
| CVE-2023-41678 | HIGH | 8.8 | 1.1% | Dec 13, 2023 | A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.... |
| CVE-2023-41673 | MEDIUM | 5.4 | 0.4% | Dec 13, 2023 | An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low pr... |
| CVE-2023-40716 | HIGH | 7.8 | 0.2% | Dec 13, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpr... |
| CVE-2023-36639 | HIGH | 8.8 | 1.1% | Dec 13, 2023 | A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, ... |
| CVE-2023-45801 | HIGH | 7.5 | 0.7% | Dec 13, 2023 | Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 b... |
| CVE-2023-47579 | HIGH | 7.5 | 0.6% | Dec 13, 2023 | Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central passwor... |
| CVE-2023-47578 | HIGH | 8.8 | 0.3% | Dec 13, 2023 | Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to ... |
| CVE-2023-47577 | CRITICAL | 9.8 | 0.7% | Dec 13, 2023 | An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no ch... |
| CVE-2023-47576 | HIGH | 8.8 | 1.5% | Dec 13, 2023 | An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection... |
| CVE-2023-47575 | MEDIUM | 6.1 | 0.4% | Dec 13, 2023 | An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices... |
| CVE-2023-47574 | MEDIUM | 5.9 | 0.5% | Dec 13, 2023 | An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. There is a Weak SMB configuration with s... |
| CVE-2023-47573 | HIGH | 8.8 | 0.7% | Dec 13, 2023 | An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface... |
| CVE-2023-45800 | HIGH | 7.5 | 0.6% | Dec 13, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro gr... |
| CVE-2023-45864 | MEDIUM | 4.7 | 0.1% | Dec 13, 2023 | A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows ... |
| CVE-2023-43122 | MEDIUM | 4.6 | 0.3% | Dec 13, 2023 | Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow In... |
| CVE-2023-42483 | MEDIUM | 4.7 | 0.1% | Dec 13, 2023 | A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exyn... |
| CVE-2023-6753 | HIGH | 8.8 | 1.1% | Dec 13, 2023 | Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. |
| CVE-2023-50263 | MEDIUM | 5.3 | 0.7% | Dec 12, 2023 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python ... |
| CVE-2023-3517 | HIGH | 8.8 | 0.6% | Dec 12, 2023 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not res... |
| CVE-2023-6710 | MEDIUM | 5.4 | 2.2% | Dec 12, 2023 | A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now