2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22292HIGH7.8Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of pr...
CVE-2023-22290MEDIUM6.5Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of servic...
CVE-2023-22285HIGH7.5Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of...
CVE-2023-20596CRITICAL9.8Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 acces...
CVE-2023-20592MEDIUM6.5Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervis...
CVE-2023-20571HIGH8.1A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage C...
CVE-2023-20568MEDIUM6.7Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privi...
CVE-2023-20567MEDIUM6.7Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privi...
CVE-2023-20566HIGH7.5Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integri...
CVE-2023-20565HIGH7.8Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of ...
CVE-2023-20563HIGH7.8Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of ...
CVE-2023-20533HIGH7.5Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an inva...
CVE-2023-20526MEDIUM4.6Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the ...
CVE-2023-20521MEDIUM5.7TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory cont...
CVE-2023-20519LOW3.3A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masque...
CVE-2023-45585LOW3.3An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 an...
CVE-2023-45582HIGH7.3An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 ...
CVE-2023-44248MEDIUM5.5An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 ...
CVE-2023-42783HIGH7.5A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4...
CVE-2023-41840HIGH7.8A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack at...
CVE-2023-41676MEDIUM6.5An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may...
CVE-2023-38177MEDIUM6.8Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-38151HIGH8.8Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
CVE-2023-36719HIGH7.8Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
CVE-2023-36705HIGH7.8Windows Installer Elevation of Privilege Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now