2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40085 | MEDIUM | 5.5 | 0.1% | Feb 16, 2024 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2023-45860 | MEDIUM | 6.5 | 0.5% | Feb 16, 2024 | In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. T... |
| CVE-2023-49508 | MEDIUM | 6.5 | 1.0% | Feb 16, 2024 | Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticat... |
| CVE-2023-40093 | MEDIUM | 5.5 | 0.1% | Feb 16, 2024 | In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in ... |
| CVE-2023-40124 | MEDIUM | 5.5 | 0.1% | Feb 15, 2024 | In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local informatio... |
| CVE-2023-40113 | MEDIUM | 5.5 | 0.1% | Feb 15, 2024 | In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission ch... |
| CVE-2023-40112 | MEDIUM | 5.5 | 0.1% | Feb 15, 2024 | In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to loc... |
| CVE-2023-40105 | MEDIUM | 5.5 | 0.1% | Feb 15, 2024 | In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing pe... |
| CVE-2023-6123 | MEDIUM | 6.1 | 0.5% | Feb 15, 2024 | Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could re... |
| CVE-2023-6937 | MEDIUM | 5.3 | 0.5% | Feb 15, 2024 | wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was ... |
| CVE-2023-47537 | MEDIUM | 4.8 | 0.2% | Feb 15, 2024 | An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, F... |
| CVE-2023-44253 | MEDIUM | 5 | 0.7% | Feb 15, 2024 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7... |
| CVE-2023-26206 | MEDIUM | 6.1 | 0.5% | Feb 15, 2024 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4... |
| CVE-2023-4538 | MEDIUM | 6.5 | 0.4% | Feb 15, 2024 | The database access credentials configured during installation are stored in a special table, and are encrypted with a s... |
| CVE-2023-46596 | MEDIUM | 6.1 | 0.3% | Feb 15, 2024 | Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File f... |
| CVE-2023-49721 | MEDIUM | 6.7 | 0.2% | Feb 14, 2024 | An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass S... |
| CVE-2023-48733 | MEDIUM | 6.7 | 0.3% | Feb 14, 2024 | An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker t... |
| CVE-2023-5122 | MEDIUM | 5.3 | 0.5% | Feb 14, 2024 | Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintai... |
| CVE-2023-42776 | MEDIUM | 5.5 | 0.2% | Feb 14, 2024 | Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenti... |
| CVE-2023-41252 | MEDIUM | 6.5 | 0.2% | Feb 14, 2024 | Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authent... |
| CVE-2023-41090 | MEDIUM | 6.4 | 0.1% | Feb 14, 2024 | Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escala... |
| CVE-2023-39941 | MEDIUM | 6.5 | 0.3% | Feb 14, 2024 | Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to pote... |
| CVE-2023-39932 | MEDIUM | 6.7 | 0.2% | Feb 14, 2024 | Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user ... |
| CVE-2023-38135 | MEDIUM | 6.7 | 0.2% | Feb 14, 2024 | Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of priv... |
| CVE-2023-36490 | MEDIUM | 5.5 | 0.2% | Feb 14, 2024 | Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now