2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-50809HIGH7.8In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly ...
CVE-2023-31315HIGH7.5Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM c...
CVE-2023-5000HIGH8.8The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortc...
CVE-2023-52209HIGH8Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This ...
CVE-2023-1577HIGH7.8A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a l...
CVE-2023-28074HIGH7.1Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and ver...
CVE-2023-33976HIGH7.5TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when no...
CVE-2023-42959HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able ...
CVE-2023-42958HIGH7.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.4. An app may be...
CVE-2023-40398HIGH8.8This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS...
CVE-2023-40396HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, wat...
CVE-2023-50700HIGH7.8Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be call...
CVE-2023-38522HIGH7.5Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to or...
CVE-2023-48362HIGH8.8XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file ...
CVE-2023-7269HIGH7.5The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation...
CVE-2023-50304HIGH8.2IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE)...
CVE-2023-7272HIGH7.5In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to caus...
CVE-2023-7010HIGH8.8Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap c...
CVE-2023-52290HIGH8.1In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from...
CVE-2023-49566HIGH8.8 In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2...
CVE-2023-46801HIGH8.8 In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution v...
CVE-2023-52885HIGH7.8In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() Aft...
CVE-2023-32472HIGH8.2Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal...
CVE-2023-32467HIGH8.2Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal...
CVE-2023-7062HIGH8.8The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now