2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0202HIGH7.8NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the ...
CVE-2023-0201MEDIUM6.7NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bound...
CVE-2023-0200MEDIUM6.7NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an ...
CVE-2023-0199MEDIUM6.1NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-...
CVE-2023-0190MEDIUM5.5NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference ...
CVE-2023-0184HIGH7.8NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead...
CVE-2023-2240HIGH8.8Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
CVE-2023-29020MEDIUM6.5@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request F...
CVE-2023-29019HIGH8.1@fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/p...
CVE-2023-2118MEDIUM5.4Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated...
CVE-2023-30621CRITICAL9.8Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 ...
CVE-2023-30620HIGH7.5mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction ...
CVE-2023-30618LOW3.3Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform co...
CVE-2023-29924CRITICAL9.8PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
CVE-2023-26557HIGH7.5io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it re...
CVE-2023-26556CRITICAL9.1io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-mu...
CVE-2023-30798HIGH7.5There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and ...
CVE-2023-2141HIGH8.8An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authenticati...
CVE-2023-2140HIGH7.5A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthe...
CVE-2023-2139MEDIUM6.1 A reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attac...
CVE-2023-2231CRITICAL9.8A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an ...
CVE-2023-29917MEDIUM4.9H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via go parameter at /goform/aspForm.
CVE-2023-29916MEDIUM4.9H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /gof...
CVE-2023-29915MEDIUM4.9H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.
CVE-2023-29914MEDIUM4.9H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /gofo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now