2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36548 | CRITICAL | 9.8 | 2.1% | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio... |
| CVE-2023-36547 | CRITICAL | 9.8 | 2.1% | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio... |
| CVE-2023-34993 | CRITICAL | 9.8 | 18.1% | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio... |
| CVE-2023-34992 | CRITICAL | 9.8 | 65.5% | Oct 10, 2023 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2023-30806 | CRITICAL | 9.8 | 65.8% | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln... |
| CVE-2023-30805 | CRITICAL | 9.8 | 65.8% | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln... |
| CVE-2023-30803 | CRITICAL | 9.8 | 18.2% | Oct 10, 2023 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A ... |
| CVE-2023-30801 | CRITICAL | 9.8 | 0.9% | Oct 10, 2023 | All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The... |
| CVE-2023-41373 | CRITICAL | 9.9 | 2.4% | Oct 10, 2023 | A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker... |
| CVE-2023-43625 | CRITICAL | 9.8 | 1.2% | Oct 10, 2023 | A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SO... |
| CVE-2023-35796 | CRITICAL | 9 | 0.6% | Oct 10, 2023 | A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly sanitizes c... |
| CVE-2023-43899 | CRITICAL | 9.8 | 0.5% | Oct 9, 2023 | hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx. |
| CVE-2023-43271 | CRITICAL | 9.1 | 0.6% | Oct 9, 2023 | Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the d... |
| CVE-2023-44467 | CRITICAL | 9.8 | 0.9% | Oct 9, 2023 | langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-202... |
| CVE-2023-44392 | CRITICAL | 9 | 0.7% | Oct 9, 2023 | Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a d... |
| CVE-2023-5365 | CRITICAL | 9.8 | 0.6% | Oct 9, 2023 | HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure. |
| CVE-2023-43696 | CRITICAL | 9.8 | 0.6% | Oct 9, 2023 | Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file... |
| CVE-2023-45613 | CRITICAL | 9.1 | 0.3% | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 server certificates were not verified |
| CVE-2023-45612 | CRITICAL | 9.8 | 0.6% | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE |
| CVE-2023-45199 | CRITICAL | 9.8 | 1.0% | Oct 7, 2023 | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. |
| CVE-2023-45311 | CRITICAL | 9.8 | 1.5% | Oct 6, 2023 | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adv... |
| CVE-2023-3725 | CRITICAL | 9.8 | 1.1% | Oct 6, 2023 | Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem |
| CVE-2023-5214 | CRITICAL | 9.8 | 0.4% | Oct 6, 2023 | In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. |
| CVE-2023-45239 | CRITICAL | 9.8 | 1.8% | Oct 6, 2023 | A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled,... |
| CVE-2023-44807 | CRITICAL | 9.8 | 1.1% | Oct 6, 2023 | D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now