2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40085MEDIUM5.5In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2023-45860MEDIUM6.5In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. T...
CVE-2023-49508MEDIUM6.5Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticat...
CVE-2023-40093MEDIUM5.5In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in ...
CVE-2023-40124MEDIUM5.5In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local informatio...
CVE-2023-40113MEDIUM5.5In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission ch...
CVE-2023-40112MEDIUM5.5In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to loc...
CVE-2023-40105MEDIUM5.5In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing pe...
CVE-2023-6123MEDIUM6.1Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could re...
CVE-2023-6937MEDIUM5.3wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was ...
CVE-2023-47537MEDIUM4.8An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, F...
CVE-2023-44253MEDIUM5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7...
CVE-2023-26206MEDIUM6.1An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4...
CVE-2023-4538MEDIUM6.5The database access credentials configured during installation are stored in a special table, and are encrypted with a s...
CVE-2023-46596MEDIUM6.1 Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File f...
CVE-2023-49721MEDIUM6.7An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass S...
CVE-2023-48733MEDIUM6.7An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker t...
CVE-2023-5122MEDIUM5.3Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintai...
CVE-2023-42776MEDIUM5.5Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenti...
CVE-2023-41252MEDIUM6.5Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authent...
CVE-2023-41090MEDIUM6.4Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escala...
CVE-2023-39941MEDIUM6.5Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to pote...
CVE-2023-39932MEDIUM6.7Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user ...
CVE-2023-38135MEDIUM6.7Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of priv...
CVE-2023-36490MEDIUM5.5Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now