2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20530 | HIGH | 7.5 | 0.6% | Jan 11, 2023 | Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resul... |
| CVE-2023-20529 | HIGH | 7.5 | 0.6% | Jan 11, 2023 | Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value poten... |
| CVE-2023-20528 | LOW | 2.4 | 0.2% | Jan 11, 2023 | Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bu... |
| CVE-2023-20527 | MEDIUM | 6.5 | 0.6% | Jan 11, 2023 | Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, po... |
| CVE-2023-20525 | MEDIUM | 6.5 | 0.6% | Jan 11, 2023 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the b... |
| CVE-2023-20523 | MEDIUM | 5.7 | 0.2% | Jan 11, 2023 | TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of inte... |
| CVE-2023-20522 | HIGH | 7.5 | 0.6% | Jan 11, 2023 | Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of servic... |
| CVE-2023-0161 | — | — | — | Jan 11, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-22963 | MEDIUM | 5.3 | 0.5% | Jan 11, 2023 | The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-... |
| CVE-2023-22959 | HIGH | 8.8 | 13.7% | Jan 11, 2023 | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstN... |
| CVE-2023-22958 | MEDIUM | 6.1 | 0.4% | Jan 11, 2023 | The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet... |
| CVE-2023-22947 | HIGH | 7.3 | 0.3% | Jan 11, 2023 | Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an u... |
| CVE-2023-22945 | MEDIUM | 4.3 | 0.5% | Jan 11, 2023 | In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (bloc... |
| CVE-2023-21793 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21792 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21791 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21790 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21789 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21788 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21787 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21786 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21785 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21784 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21783 | HIGH | 7.8 | 1.1% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
| CVE-2023-21782 | HIGH | 7.8 | 0.9% | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now