2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42667 | HIGH | 7.8 | 0.2% | Aug 14, 2024 | Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to po... |
| CVE-2023-40067 | MEDIUM | 5.7 | 0.2% | Aug 14, 2024 | Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to potentially enable escala... |
| CVE-2023-38655 | MEDIUM | 6.9 | 0.5% | Aug 14, 2024 | Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privilege... |
| CVE-2023-35123 | MEDIUM | 5.9 | 0.4% | Aug 14, 2024 | Uncaught exception in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.14-0, bhs-0.27 may allow... |
| CVE-2023-34424 | MEDIUM | 6.7 | 0.2% | Aug 14, 2024 | Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of... |
| CVE-2023-31366 | MEDIUM | 5.5 | 0.1% | Aug 13, 2024 | Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially res... |
| CVE-2023-31356 | MEDIUM | 4.4 | 0.2% | Aug 13, 2024 | Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, pote... |
| CVE-2023-31349 | HIGH | 7.8 | 0.2% | Aug 13, 2024 | Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escal... |
| CVE-2023-31348 | HIGH | 7.8 | 0.2% | Aug 13, 2024 | A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resultin... |
| CVE-2023-31341 | MEDIUM | 5.5 | 0.1% | Aug 13, 2024 | Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacke... |
| CVE-2023-31339 | MEDIUM | 5.8 | 0.2% | Aug 13, 2024 | Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged ... |
| CVE-2023-31310 | MEDIUM | 5 | 0.1% | Aug 13, 2024 | Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed ... |
| CVE-2023-31307 | MEDIUM | 4.4 | 0.2% | Aug 13, 2024 | Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o... |
| CVE-2023-31305 | LOW | 1.9 | 0.1% | Aug 13, 2024 | Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker ... |
| CVE-2023-31304 | LOW | 2.3 | 0.2% | Aug 13, 2024 | Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to ... |
| CVE-2023-20591 | CRITICAL | 10 | 0.3% | Aug 13, 2024 | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, all... |
| CVE-2023-20584 | MEDIUM | 6 | 0.2% | Aug 13, 2024 | IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an att... |
| CVE-2023-20578 | MEDIUM | 6.4 | 0.1% | Aug 13, 2024 | A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or U... |
| CVE-2023-20518 | LOW | 1.9 | 0.1% | Aug 13, 2024 | Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIO... |
| CVE-2023-20513 | LOW | 3.3 | 0.1% | Aug 13, 2024 | An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtua... |
| CVE-2023-20512 | LOW | 1.9 | 0.1% | Aug 13, 2024 | A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in in... |
| CVE-2023-20510 | MEDIUM | 6 | 0.1% | Aug 13, 2024 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ... |
| CVE-2023-20509 | MEDIUM | 5.2 | 0.1% | Aug 13, 2024 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DR... |
| CVE-2023-26211 | CRITICAL | 9 | 0.7% | Aug 13, 2024 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 thro... |
| CVE-2023-7066 | HIGH | 7.8 | 0.2% | Aug 12, 2024 | The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now