2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40717 | HIGH | 7.8 | 0.2% | Sep 13, 2023 | A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who man... |
| CVE-2023-40715 | MEDIUM | 5.5 | 0.2% | Sep 13, 2023 | A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an att... |
| CVE-2023-36642 | HIGH | 7.8 | 0.2% | Sep 13, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface ... |
| CVE-2023-36638 | MEDIUM | 4.3 | 0.3% | Sep 13, 2023 | An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0... |
| CVE-2023-36634 | HIGH | 8.8 | 0.5% | Sep 13, 2023 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr... |
| CVE-2023-36551 | MEDIUM | 5.3 | 0.6% | Sep 13, 2023 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows at... |
| CVE-2023-34984 | HIGH | 8.8 | 0.7% | Sep 13, 2023 | A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6... |
| CVE-2023-29183 | MEDIUM | 5.4 | 1.1% | Sep 13, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiP... |
| CVE-2023-27998 | MEDIUM | 5.3 | 0.4% | Sep 13, 2023 | A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1... |
| CVE-2023-25608 | MEDIUM | 6.5 | 0.5% | Sep 13, 2023 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr... |
| CVE-2023-41081 | HIGH | 7.5 | 1.3% | Sep 13, 2023 | Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances,... |
| CVE-2023-4039 | MEDIUM | 4.8 | 0.7% | Sep 13, 2023 | **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker t... |
| CVE-2023-29306 | MEDIUM | 6.1 | 0.4% | Sep 13, 2023 | Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta... |
| CVE-2023-29305 | MEDIUM | 6.1 | 0.4% | Sep 13, 2023 | Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta... |
| CVE-2023-26369 | HIGH | 7.8 | 7.0% | Sep 13, 2023 | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affect... |
| CVE-2023-4400 | MEDIUM | 6.5 | 0.3% | Sep 13, 2023 | A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x pr... |
| CVE-2023-4917 | MEDIUM | 6.5 | 0.6% | Sep 13, 2023 | The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 ... |
| CVE-2023-4916 | HIGH | 8.8 | 0.3% | Sep 13, 2023 | The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2023-4915 | MEDIUM | 5.3 | 0.4% | Sep 13, 2023 | The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including ... |
| CVE-2023-4213 | HIGH | 8.8 | 0.6% | Sep 13, 2023 | The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions u... |
| CVE-2023-4153 | HIGH | 8.8 | 0.7% | Sep 13, 2023 | The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to ... |
| CVE-2023-4928 | HIGH | 7.2 | 0.7% | Sep 13, 2023 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4813 | MEDIUM | 5.9 | 1.7% | Sep 12, 2023 | A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed... |
| CVE-2023-41423 | MEDIUM | 5.4 | 0.5% | Sep 12, 2023 | Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-39073 | CRITICAL | 9.8 | 0.9% | Sep 12, 2023 | An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now