2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43525HIGH7.8Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
CVE-2023-43524HIGH7.8Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
CVE-2023-43521HIGH7.8Memory corruption when multiple listeners are being registered with the same file descriptor.
CVE-2023-33119HIGH7Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
CVE-2023-49676MEDIUM5.5An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after ...
CVE-2023-49675HIGH7.8An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash th...
CVE-2023-6854MEDIUM6.4The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output...
CVE-2023-32873MEDIUM6.7In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio...
CVE-2023-32871MEDIUM5.3In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of pr...
CVE-2023-52729HIGH7.5TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add ...
CVE-2023-27283MEDIUM5.3IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepanc...
CVE-2023-7065MEDIUM5.4The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2023-40695HIGH8.8IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authentic...
CVE-2023-40696HIGH7.5IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an ...
CVE-2023-38724CRITICAL9.8IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially ...
CVE-2023-28952MEDIUM5.3IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not saniti...
CVE-2023-23474MEDIUM5.3IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a st...
CVE-2023-37407HIGH8.8IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by...
CVE-2023-6363MEDIUM5.1Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2023-41830MEDIUM6.5 An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local applicati...
CVE-2023-41828MEDIUM4.4 An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized a...
CVE-2023-41826MEDIUM5.1A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to ...
CVE-2023-41825LOW2.8 A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to ...
CVE-2023-41824LOW2.8 An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker...
CVE-2023-41823MEDIUM4.4 An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local att...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now