2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22342HIGH7.7Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authen...
CVE-2023-22311HIGH7.8Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may...
CVE-2023-22293HIGH8.2Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to poten...
CVE-2023-48987HIGH7.5Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a re...
CVE-2023-48986MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allo...
CVE-2023-48985MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allo...
CVE-2023-44294MEDIUM6.5 In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), ...
CVE-2023-44293MEDIUM6.5 In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), ...
CVE-2023-44283HIGH7.8 In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4...
CVE-2023-39249MEDIUM5.3 Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows loca...
CVE-2023-25535MEDIUM6.5 Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has ...
CVE-2023-38960HIGH7.3Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain pri...
CVE-2023-6152MEDIUM5.4A user changing their email after signing up and verifying it can change it without verification in profile settings. T...
CVE-2023-31347MEDIUM4.9Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an ...
CVE-2023-31346MEDIUM6Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. ...
CVE-2023-20587HIGH7.1Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leadin...
CVE-2023-20579MEDIUM6Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to...
CVE-2023-50808MEDIUM6.1Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
CVE-2023-20570LOW3.3Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentia...
CVE-2023-48432MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can o...
CVE-2023-45207MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through...
CVE-2023-45206MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webma...
CVE-2023-26562MEDIUM6.5In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messag...
CVE-2023-6516HIGH7.5To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the data...
CVE-2023-5680MEDIUM5.3If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now