2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48171 | HIGH | 8.8 | 0.6% | Aug 12, 2024 | An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions c... |
| CVE-2023-41884 | MEDIUM | 6.5 | 0.5% | Aug 12, 2024 | ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes ... |
| CVE-2023-7249 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Direct... |
| CVE-2023-50810 | MEDIUM | 6 | 0.8% | Aug 12, 2024 | In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot compon... |
| CVE-2023-50809 | HIGH | 7.8 | 0.4% | Aug 12, 2024 | In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly ... |
| CVE-2023-38018 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user... |
| CVE-2023-31315 | HIGH | 7.5 | 0.6% | Aug 12, 2024 | Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM c... |
| CVE-2023-40261 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails... |
| CVE-2023-33206 | MEDIUM | 6.8 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails... |
| CVE-2023-28865 | MEDIUM | 6.6 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate... |
| CVE-2023-24064 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authoriz... |
| CVE-2023-24063 | MEDIUM | 6.8 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authoriza... |
| CVE-2023-24062 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate... |
| CVE-2023-7265 | MEDIUM | 6.2 | 0.1% | Aug 8, 2024 | Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability ma... |
| CVE-2023-28806 | MEDIUM | 6.5 | 0.2% | Aug 6, 2024 | An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-... |
| CVE-2023-40819 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injec... |
| CVE-2023-5000 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortc... |
| CVE-2023-31355 | MEDIUM | 6 | 0.4% | Aug 5, 2024 | Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC s... |
| CVE-2023-52209 | HIGH | 8 | 0.3% | Aug 1, 2024 | Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This ... |
| CVE-2023-1577 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a l... |
| CVE-2023-28149 | MEDIUM | 6.1 | 0.1% | Jul 31, 2024 | An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05... |
| CVE-2023-28074 | HIGH | 7.1 | 0.1% | Jul 31, 2024 | Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and ver... |
| CVE-2023-33976 | HIGH | 7.5 | 0.4% | Jul 30, 2024 | TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when no... |
| CVE-2023-38001 | MEDIUM | 6.5 | 0.2% | Jul 30, 2024 | IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... |
| CVE-2023-26289 | MEDIUM | 5.4 | 0.3% | Jul 30, 2024 | IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now