2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27997CRITICAL9.8A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi...
CVE-2023-27465MEDIUM4.6A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >...
CVE-2023-26210HIGH7.8Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-...
CVE-2023-26207MEDIUM6.5An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy...
CVE-2023-26204CRITICAL9.8A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi...
CVE-2023-25910HIGH8.8A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 ...
CVE-2023-25609MEDIUM6.5A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, ...
CVE-2023-22639HIGH7.8A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS ver...
CVE-2023-22633HIGH7.5An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and...
CVE-2023-2729HIGH7.5Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM)...
CVE-2023-2673MEDIUM5.3Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packet...
CVE-2023-0142HIGH8.1Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) ...
CVE-2023-2876MEDIUM6.1Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware ...
CVE-2023-33991HIGH8.2SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not s...
CVE-2023-33986MEDIUM6.1SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled ...
CVE-2023-33985MEDIUM6.1SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, re...
CVE-2023-33984MEDIUM5.4SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, whi...
CVE-2023-32115MEDIUM6.1An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resultin...
CVE-2023-32114LOW2.7SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an ...
CVE-2023-2827MEDIUM5.7SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do ...
CVE-2023-2563MEDIUM4.3The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t...
CVE-2023-2351MEDIUM4.3The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m...
CVE-2023-2278CRITICAL9.8The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 ...
CVE-2023-2277MEDIUM4.7The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-32674CRITICAL9.8Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now