2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36016LOW3.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-34991CRITICAL9.8A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6....
CVE-2023-33304MEDIUM5.5A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an ...
CVE-2023-28002MEDIUM6.7An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7....
CVE-2023-26205HIGH8.8An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions,...
CVE-2023-6131HIGH8.8 Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-6130HIGH8.8Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-48094MEDIUM6.1A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context ...
CVE-2023-47660MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Wham Product Visibility by Country for WooCommerce ...
CVE-2023-47659MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34...
CVE-2023-6128MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-6127MEDIUM5.4Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4...
CVE-2023-6126CRITICAL9.8 Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-6125HIGH8.8 Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
CVE-2023-47262MEDIUM5.2The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modifi...
CVE-2023-6124MEDIUM4.3Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
CVE-2023-48021HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.
CVE-2023-48020HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeSta...
CVE-2023-45684HIGH7.5Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earl...
CVE-2023-6111HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-46601HIGH7.5A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in ma...
CVE-2023-46590HIGH7.5A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products ...
CVE-2023-46099MEDIUM4.8A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vul...
CVE-2023-46098HIGH8.8A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from...
CVE-2023-46097HIGH8A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now