2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42667HIGH7.8Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to po...
CVE-2023-40067MEDIUM5.7Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to potentially enable escala...
CVE-2023-38655MEDIUM6.9Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privilege...
CVE-2023-35123MEDIUM5.9Uncaught exception in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.14-0, bhs-0.27 may allow...
CVE-2023-34424MEDIUM6.7Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of...
CVE-2023-31366MEDIUM5.5Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially res...
CVE-2023-31356MEDIUM4.4Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, pote...
CVE-2023-31349HIGH7.8Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escal...
CVE-2023-31348HIGH7.8A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resultin...
CVE-2023-31341MEDIUM5.5Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacke...
CVE-2023-31339MEDIUM5.8Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged ...
CVE-2023-31310MEDIUM5Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed ...
CVE-2023-31307MEDIUM4.4Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o...
CVE-2023-31305LOW1.9Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker ...
CVE-2023-31304LOW2.3Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to ...
CVE-2023-20591CRITICAL10Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, all...
CVE-2023-20584MEDIUM6IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an att...
CVE-2023-20578MEDIUM6.4A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or U...
CVE-2023-20518LOW1.9Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIO...
CVE-2023-20513LOW3.3An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtua...
CVE-2023-20512LOW1.9A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in in...
CVE-2023-20510MEDIUM6An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ...
CVE-2023-20509MEDIUM5.2An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DR...
CVE-2023-26211CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 thro...
CVE-2023-7066HIGH7.8The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now