2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6044 | MEDIUM | 6.8 | 0.2% | Jan 19, 2024 | A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical acce... |
| CVE-2023-33295 | MEDIUM | 6.5 | 0.3% | Jan 19, 2024 | Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a l... |
| CVE-2023-32544 | MEDIUM | 5.5 | 0.1% | Jan 19, 2024 | Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installe... |
| CVE-2023-32272 | MEDIUM | 5.5 | 0.2% | Jan 19, 2024 | Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.... |
| CVE-2023-51946 | MEDIUM | 6.1 | 0.6% | Jan 19, 2024 | Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow... |
| CVE-2023-50963 | MEDIUM | 5.4 | 0.3% | Jan 19, 2024 | IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper valid... |
| CVE-2023-32337 | MEDIUM | 5.4 | 0.3% | Jan 19, 2024 | IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2023-35020 | MEDIUM | 5.3 | 0.5% | Jan 19, 2024 | IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could... |
| CVE-2023-51258 | MEDIUM | 5.5 | 0.3% | Jan 18, 2024 | A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token fu... |
| CVE-2023-49943 | MEDIUM | 5.4 | 1.8% | Jan 18, 2024 | Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name... |
| CVE-2023-31274 | MEDIUM | 5.3 | 0.5% | Jan 18, 2024 | AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated us... |
| CVE-2023-28901 | MEDIUM | 5.3 | 0.5% | Jan 18, 2024 | The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent tr... |
| CVE-2023-28900 | MEDIUM | 5.3 | 0.4% | Jan 18, 2024 | The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user i... |
| CVE-2023-7153 | MEDIUM | 6.1 | 0.3% | Jan 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software... |
| CVE-2023-51464 | MEDIUM | 5.4 | 0.4% | Jan 18, 2024 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-51463 | MEDIUM | 5.4 | 0.4% | Jan 18, 2024 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2023-6970 | MEDIUM | 6.1 | 0.7% | Jan 18, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all... |
| CVE-2023-6958 | MEDIUM | 5.4 | 0.3% | Jan 18, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a... |
| CVE-2023-48359 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local d... |
| CVE-2023-48358 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of... |
| CVE-2023-48357 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of... |
| CVE-2023-48356 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of... |
| CVE-2023-48355 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of... |
| CVE-2023-48354 | MEDIUM | 5.5 | 0.1% | Jan 18, 2024 | In telephone service, there is a possible improper input validation. This could lead to local information disclosure wit... |
| CVE-2023-48353 | MEDIUM | 4.4 | 0.1% | Jan 18, 2024 | In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now