2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36548CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-36547CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34993CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2023-34992CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2023-30806CRITICAL9.8The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln...
CVE-2023-30805CRITICAL9.8The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln...
CVE-2023-30803CRITICAL9.8The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A ...
CVE-2023-30801CRITICAL9.8All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The...
CVE-2023-41373CRITICAL9.9 A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker...
CVE-2023-43625CRITICAL9.8A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SO...
CVE-2023-35796CRITICAL9A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly sanitizes c...
CVE-2023-43899CRITICAL9.8hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
CVE-2023-43271CRITICAL9.1Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the d...
CVE-2023-44467CRITICAL9.8langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-202...
CVE-2023-44392CRITICAL9Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a d...
CVE-2023-5365CRITICAL9.8HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
CVE-2023-43696CRITICAL9.8 Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file...
CVE-2023-45613CRITICAL9.1In JetBrains Ktor before 2.3.5 server certificates were not verified
CVE-2023-45612CRITICAL9.8In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
CVE-2023-45199CRITICAL9.8Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-45311CRITICAL9.8fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adv...
CVE-2023-3725CRITICAL9.8Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
CVE-2023-5214CRITICAL9.8In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
CVE-2023-45239CRITICAL9.8A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled,...
CVE-2023-44807CRITICAL9.8D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now