2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20601 | MEDIUM | 4.6 | 0.2% | Feb 12, 2026 | Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially re... |
| CVE-2023-31313 | HIGH | 7.2 | 0.1% | Feb 12, 2026 | An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to sen... |
| CVE-2023-31324 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ... |
| CVE-2023-20548 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt... |
| CVE-2023-20514 | HIGH | 8.7 | 0.1% | Feb 11, 2026 | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary... |
| CVE-2023-6763 | — | — | — | Feb 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-38281 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able... |
| CVE-2023-38017 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip... |
| CVE-2023-38010 | HIGH | 7.5 | 0.3% | Feb 4, 2026 | IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste... |
| CVE-2023-54343 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to in... |
| CVE-2023-37525 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF d... |
| CVE-2023-7335 | HIGH | 8.7 | 0.7% | Jan 22, 2026 | EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export ... |
| CVE-2023-32720 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-32719 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-32718 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22944 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22930 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22929 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22928 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22927 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22926 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-22925 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2023-7334 | CRITICAL | 9.8 | 1.0% | Jan 15, 2026 | Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha... |
| CVE-2023-54341 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to... |
| CVE-2023-54340 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now