2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6044MEDIUM6.8A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical acce...
CVE-2023-33295MEDIUM6.5Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a l...
CVE-2023-32544MEDIUM5.5Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installe...
CVE-2023-32272MEDIUM5.5Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0....
CVE-2023-51946MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow...
CVE-2023-50963MEDIUM5.4IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper valid...
CVE-2023-32337MEDIUM5.4IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2023-35020MEDIUM5.3IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could...
CVE-2023-51258MEDIUM5.5A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token fu...
CVE-2023-49943MEDIUM5.4Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name...
CVE-2023-31274MEDIUM5.3 AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated us...
CVE-2023-28901MEDIUM5.3The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent tr...
CVE-2023-28900MEDIUM5.3The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user i...
CVE-2023-7153MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software...
CVE-2023-51464MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2023-51463MEDIUM5.4Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2023-6970MEDIUM6.1The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all...
CVE-2023-6958MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a...
CVE-2023-48359MEDIUM4.4In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local d...
CVE-2023-48358MEDIUM4.4In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of...
CVE-2023-48357MEDIUM4.4In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of...
CVE-2023-48356MEDIUM4.4In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of...
CVE-2023-48355MEDIUM4.4In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of...
CVE-2023-48354MEDIUM5.5In telephone service, there is a possible improper input validation. This could lead to local information disclosure wit...
CVE-2023-48353MEDIUM4.4In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now