2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20601MEDIUM4.6Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially re...
CVE-2023-31313HIGH7.2An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to sen...
CVE-2023-31324HIGH7.8A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ...
CVE-2023-20548HIGH7.8A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt...
CVE-2023-20514HIGH8.7Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary...
CVE-2023-6763Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-38281MEDIUM5.3IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able...
CVE-2023-38017MEDIUM5.3IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip...
CVE-2023-38010HIGH7.5IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste...
CVE-2023-54343MEDIUM6.4QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to in...
CVE-2023-37525MEDIUM5.3A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF d...
CVE-2023-7335HIGH8.7EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export ...
CVE-2023-32720Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-32719Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-32718Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22944Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22930Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22929Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22928Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22927Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22926Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-22925Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2023-7334CRITICAL9.8Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha...
CVE-2023-54341MEDIUM6.1Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to...
CVE-2023-54340HIGH8.8WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now