2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42788MEDIUM6.7An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2023-42787MEDIUM6.5A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and bef...
CVE-2023-42782MEDIUM5.3A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 ...
CVE-2023-41841HIGH8.8An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belongin...
CVE-2023-41838HIGH7.1An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and ...
CVE-2023-41679CRITICAL9.6An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 throu...
CVE-2023-41675MEDIUM5.3A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and For...
CVE-2023-40718HIGH7.5A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features v...
CVE-2023-37939LOW3.3An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, ...
CVE-2023-37935HIGH7.5A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5...
CVE-2023-36637MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through...
CVE-2023-36556HIGH8.8An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 throu...
CVE-2023-36555MEDIUM5.4An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allow...
CVE-2023-36550CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-36549CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-36548CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-36547CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-36478HIGH7.5Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, a...
CVE-2023-34993CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34992CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2023-34989HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34988HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34987HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34986HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34985HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now