2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43525 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption while copying the sound model data from user to kernel buffer during sound model register. |
| CVE-2023-43524 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when the bandpass filter order received from AHAL is not within the expected range. |
| CVE-2023-43521 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when multiple listeners are being registered with the same file descriptor. |
| CVE-2023-33119 | HIGH | 7 | 0.1% | May 6, 2024 | Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. |
| CVE-2023-49676 | MEDIUM | 5.5 | 0.2% | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after ... |
| CVE-2023-49675 | HIGH | 7.8 | 0.2% | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash th... |
| CVE-2023-6854 | MEDIUM | 6.4 | 0.3% | May 6, 2024 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output... |
| CVE-2023-32873 | MEDIUM | 6.7 | 0.1% | May 6, 2024 | In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2023-32871 | MEDIUM | 5.3 | 0.1% | May 6, 2024 | In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of pr... |
| CVE-2023-52729 | HIGH | 7.5 | 0.5% | May 4, 2024 | TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add ... |
| CVE-2023-27283 | MEDIUM | 5.3 | 0.5% | May 4, 2024 | IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepanc... |
| CVE-2023-7065 | MEDIUM | 5.4 | 0.2% | May 4, 2024 | The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2023-40695 | HIGH | 8.8 | 0.4% | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authentic... |
| CVE-2023-40696 | HIGH | 7.5 | 0.3% | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an ... |
| CVE-2023-38724 | CRITICAL | 9.8 | 0.5% | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially ... |
| CVE-2023-28952 | MEDIUM | 5.3 | 0.4% | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not saniti... |
| CVE-2023-23474 | MEDIUM | 5.3 | 0.4% | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a st... |
| CVE-2023-37407 | HIGH | 8.8 | 0.9% | May 3, 2024 | IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by... |
| CVE-2023-6363 | MEDIUM | 5.1 | 0.2% | May 3, 2024 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2023-41830 | MEDIUM | 6.5 | 0.2% | May 3, 2024 | An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local applicati... |
| CVE-2023-41828 | MEDIUM | 4.4 | 0.2% | May 3, 2024 | An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized a... |
| CVE-2023-41826 | MEDIUM | 5.1 | 0.2% | May 3, 2024 | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to ... |
| CVE-2023-41825 | LOW | 2.8 | 0.2% | May 3, 2024 | A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to ... |
| CVE-2023-41824 | LOW | 2.8 | 0.1% | May 3, 2024 | An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker... |
| CVE-2023-41823 | MEDIUM | 4.4 | 0.2% | May 3, 2024 | An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local att... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now