2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48297 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@... |
| CVE-2023-42463 | HIGH | 7.8 | 0.2% | Jan 12, 2024 | Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stac... |
| CVE-2023-6683 | MEDIUM | 6.5 | 1.3% | Jan 12, 2024 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f... |
| CVE-2023-31035 | HIGH | 7.8 | 0.2% | Jan 12, 2024 | NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be us... |
| CVE-2023-31034 | HIGH | 7.8 | 0.2% | Jan 12, 2024 | NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed b... |
| CVE-2023-31033 | HIGH | 8 | 0.3% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical functi... |
| CVE-2023-31032 | MEDIUM | 5.5 | 0.2% | Jan 12, 2024 | NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A s... |
| CVE-2023-31031 | HIGH | 7.8 | 0.2% | Jan 12, 2024 | NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer o... |
| CVE-2023-31030 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack... |
| CVE-2023-31029 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthen... |
| CVE-2023-31025 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of... |
| CVE-2023-31024 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack m... |
| CVE-2023-46805 | HIGH | 8.2 | 100.0% | Jan 12, 2024 | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re... |
| CVE-2023-31036 | HIGH | 8.8 | 0.9% | Jan 12, 2024 | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-de... |
| CVE-2023-28899 | MEDIUM | 5.5 | 0.1% | Jan 12, 2024 | By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdow... |
| CVE-2023-51978 | MEDIUM | 6.5 | 0.5% | Jan 12, 2024 | In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerab... |
| CVE-2023-28898 | MEDIUM | 5.3 | 0.2% | Jan 12, 2024 | The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when... |
| CVE-2023-28897 | CRITICAL | 9.8 | 0.3% | Jan 12, 2024 | The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulner... |
| CVE-2023-51949 | HIGH | 8.8 | 0.3% | Jan 12, 2024 | Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/back... |
| CVE-2023-49262 | CRITICAL | 9.8 | 0.7% | Jan 12, 2024 | The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided the... |
| CVE-2023-49261 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | The "tokenKey" value used in user authorization is visible in the HTML source of the login page. |
| CVE-2023-49260 | MEDIUM | 6.1 | 0.3% | Jan 12, 2024 | An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It c... |
| CVE-2023-49259 | HIGH | 7.5 | 0.3% | Jan 12, 2024 | The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and... |
| CVE-2023-49258 | MEDIUM | 6.1 | 0.3% | Jan 12, 2024 | User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS v... |
| CVE-2023-49257 | HIGH | 8.8 | 0.3% | Jan 12, 2024 | An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execut... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now