2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-24542MEDIUM6.7Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an ...
CVE-2023-24481MEDIUM6.3Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti...
CVE-2023-24463MEDIUM4.3Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauth...
CVE-2023-22848MEDIUM5.5Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti...
CVE-2023-22390MEDIUM6.5Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an aut...
CVE-2023-48986MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allo...
CVE-2023-48985MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allo...
CVE-2023-44294MEDIUM6.5 In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), ...
CVE-2023-44293MEDIUM6.5 In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), ...
CVE-2023-39249MEDIUM5.3 Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows loca...
CVE-2023-25535MEDIUM6.5 Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has ...
CVE-2023-6152MEDIUM5.4A user changing their email after signing up and verifying it can change it without verification in profile settings. T...
CVE-2023-31347MEDIUM4.9Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an ...
CVE-2023-31346MEDIUM6Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. ...
CVE-2023-20579MEDIUM6Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to...
CVE-2023-50808MEDIUM6.1Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
CVE-2023-48432MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can o...
CVE-2023-45207MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through...
CVE-2023-45206MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webma...
CVE-2023-26562MEDIUM6.5In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messag...
CVE-2023-5680MEDIUM5.3If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache d...
CVE-2023-6072MEDIUM5.4 A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authentica...
CVE-2023-48364MEDIUM6.5A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions <...
CVE-2023-48363MEDIUM6.5A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions <...
CVE-2023-6815MEDIUM6.5Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now