2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33307 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 ... |
| CVE-2023-33306 | MEDIUM | 6.5 | 0.8% | Jun 16, 2023 | A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 a... |
| CVE-2023-2831 | MEDIUM | 6.5 | 0.7% | Jun 16, 2023 | Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Servi... |
| CVE-2023-2797 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting ... |
| CVE-2023-2793 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an at... |
| CVE-2023-2792 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a sp... |
| CVE-2023-2785 | MEDIUM | 4.3 | 0.6% | Jun 16, 2023 | Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to c... |
| CVE-2023-2791 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated... |
| CVE-2023-2788 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm... |
| CVE-2023-2787 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary po... |
| CVE-2023-2786 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post... |
| CVE-2023-2784 | MEDIUM | 6.5 | 0.3% | Jun 16, 2023 | Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowin... |
| CVE-2023-2783 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to... |
| CVE-2023-26541 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions. |
| CVE-2023-26013 | MEDIUM | 5.4 | 0.4% | Jun 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 vers... |
| CVE-2023-25963 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions. |
| CVE-2023-2431 | MEDIUM | 5.5 | 0.3% | Jun 16, 2023 | A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use loc... |
| CVE-2023-34165 | MEDIUM | 5.3 | 0.3% | Jun 16, 2023 | Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vul... |
| CVE-2023-34157 | MEDIUM | 6.5 | 0.4% | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up wi... |
| CVE-2023-34154 | HIGH | 8.2 | 0.3% | Jun 16, 2023 | Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will... |
| CVE-2023-35708 | CRITICAL | 9.8 | 92.1% | Jun 16, 2023 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.... |
| CVE-2023-34845 | MEDIUM | 5.4 | 0.8% | Jun 16, 2023 | Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. Thi... |
| CVE-2023-32754 | CRITICAL | 9.8 | 1.0% | Jun 16, 2023 | Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker c... |
| CVE-2023-32753 | CRITICAL | 9.8 | 0.9% | Jun 16, 2023 | OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote at... |
| CVE-2023-32752 | CRITICAL | 9.8 | 0.9% | Jun 16, 2023 | L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dan... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now