2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33307MEDIUM6.5A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 ...
CVE-2023-33306MEDIUM6.5A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 a...
CVE-2023-2831MEDIUM6.5Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Servi...
CVE-2023-2797MEDIUM6.5Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting ...
CVE-2023-2793MEDIUM6.5Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an at...
CVE-2023-2792MEDIUM6.5Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a sp...
CVE-2023-2785MEDIUM4.3Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to c...
CVE-2023-2791MEDIUM4.3When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated...
CVE-2023-2788MEDIUM6.5Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm...
CVE-2023-2787MEDIUM6.5Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary po...
CVE-2023-2786MEDIUM4.3Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post...
CVE-2023-2784MEDIUM6.5Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowin...
CVE-2023-2783MEDIUM4.3Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to...
CVE-2023-26541MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions.
CVE-2023-26013MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 vers...
CVE-2023-25963MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.
CVE-2023-2431MEDIUM5.5A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use loc...
CVE-2023-34165MEDIUM5.3Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vul...
CVE-2023-34157MEDIUM6.5Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up wi...
CVE-2023-34154HIGH8.2Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will...
CVE-2023-35708CRITICAL9.8In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023....
CVE-2023-34845MEDIUM5.4Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. Thi...
CVE-2023-32754CRITICAL9.8Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker c...
CVE-2023-32753CRITICAL9.8OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote at...
CVE-2023-32752CRITICAL9.8L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dan...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now