2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31273 | CRITICAL | 9.8 | 0.7% | Nov 14, 2023 | Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentia... |
| CVE-2023-25603 | CRITICAL | 9.1 | 0.4% | Nov 14, 2023 | A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.... |
| CVE-2023-20596 | CRITICAL | 9.8 | 1.0% | Nov 14, 2023 | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 acces... |
| CVE-2023-36553 | CRITICAL | 9.8 | 1.9% | Nov 14, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versi... |
| CVE-2023-36397 | CRITICAL | 9.8 | 17.6% | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
| CVE-2023-36028 | CRITICAL | 9.8 | 2.9% | Nov 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
| CVE-2023-36018 | CRITICAL | 9.8 | 1.5% | Nov 14, 2023 | Visual Studio Code Jupyter Extension Spoofing Vulnerability |
| CVE-2023-34991 | CRITICAL | 9.8 | 28.8% | Nov 14, 2023 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.... |
| CVE-2023-6126 | CRITICAL | 9.8 | 0.7% | Nov 14, 2023 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. |
| CVE-2023-44373 | CRITICAL | 9.4 | 1.4% | Nov 14, 2023 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini... |
| CVE-2023-43504 | CRITICAL | 9.8 | 0.9% | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validat... |
| CVE-2023-31247 | CRITICAL | 9.8 | 1.7% | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP... |
| CVE-2023-28391 | CRITICAL | 9.8 | 1.5% | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.0... |
| CVE-2023-28379 | CRITICAL | 9.8 | 1.7% | Nov 14, 2023 | A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01... |
| CVE-2023-27882 | CRITICAL | 9.8 | 1.8% | Nov 14, 2023 | A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-H... |
| CVE-2023-25181 | CRITICAL | 9.8 | 1.7% | Nov 14, 2023 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. ... |
| CVE-2023-24585 | CRITICAL | 9.8 | 1.2% | Nov 14, 2023 | An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A spec... |
| CVE-2023-45878 | CRITICAL | 9.8 | 63.1% | Nov 14, 2023 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not ... |
| CVE-2023-43902 | CRITICAL | 9.8 | 0.9% | Nov 14, 2023 | Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to acc... |
| CVE-2023-6102 | CRITICAL | 9.8 | 0.8% | Nov 13, 2023 | A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affect... |
| CVE-2023-6099 | CRITICAL | 9.8 | 0.9% | Nov 13, 2023 | A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up... |
| CVE-2023-6084 | CRITICAL | 9.8 | 0.9% | Nov 12, 2023 | A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknow... |
| CVE-2023-46850 | CRITICAL | 9.8 | 2.0% | Nov 11, 2023 | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execut... |
| CVE-2023-4804 | CRITICAL | 9.8 | 0.8% | Nov 10, 2023 | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. |
| CVE-2023-47129 | CRITICAL | 9.8 | 1.1% | Nov 10, 2023 | Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now