2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48297HIGH7.5Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@...
CVE-2023-42463HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stac...
CVE-2023-6683MEDIUM6.5A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f...
CVE-2023-31035HIGH7.8NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be us...
CVE-2023-31034HIGH7.8NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed b...
CVE-2023-31033HIGH8NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical functi...
CVE-2023-31032MEDIUM5.5NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A s...
CVE-2023-31031HIGH7.8NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer o...
CVE-2023-31030CRITICAL9.8NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack...
CVE-2023-31029CRITICAL9.8NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthen...
CVE-2023-31025HIGH7.5NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of...
CVE-2023-31024CRITICAL9.8NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack m...
CVE-2023-46805HIGH8.2An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re...
CVE-2023-31036HIGH8.8NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-de...
CVE-2023-28899MEDIUM5.5By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdow...
CVE-2023-51978MEDIUM6.5In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerab...
CVE-2023-28898MEDIUM5.3The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when...
CVE-2023-28897CRITICAL9.8The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulner...
CVE-2023-51949HIGH8.8Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/back...
CVE-2023-49262CRITICAL9.8The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided the...
CVE-2023-49261HIGH7.5The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
CVE-2023-49260MEDIUM6.1An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It c...
CVE-2023-49259HIGH7.5The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and...
CVE-2023-49258MEDIUM6.1User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS v...
CVE-2023-49257HIGH8.8An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execut...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now