2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48171HIGH8.8An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions c...
CVE-2023-41884MEDIUM6.5ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes ...
CVE-2023-7249CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Direct...
CVE-2023-50810MEDIUM6In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot compon...
CVE-2023-50809HIGH7.8In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly ...
CVE-2023-38018MEDIUM5.4IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user...
CVE-2023-31315HIGH7.5Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM c...
CVE-2023-40261MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails...
CVE-2023-33206MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails...
CVE-2023-28865MEDIUM6.6Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate...
CVE-2023-24064MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authoriz...
CVE-2023-24063MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authoriza...
CVE-2023-24062MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate...
CVE-2023-7265MEDIUM6.2Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability ma...
CVE-2023-28806MEDIUM6.5An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-...
CVE-2023-40819MEDIUM6.1ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injec...
CVE-2023-5000HIGH8.8The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortc...
CVE-2023-31355MEDIUM6Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC s...
CVE-2023-52209HIGH8Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This ...
CVE-2023-1577HIGH7.8A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a l...
CVE-2023-28149MEDIUM6.1An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05...
CVE-2023-28074HIGH7.1Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and ver...
CVE-2023-33976HIGH7.5TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when no...
CVE-2023-38001MEDIUM6.5IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malic...
CVE-2023-26289MEDIUM5.4IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now