2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-20578MEDIUM6.4A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or U...
CVE-2023-20510MEDIUM6An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ...
CVE-2023-20509MEDIUM5.2An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DR...
CVE-2023-41884MEDIUM6.5ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes ...
CVE-2023-50810MEDIUM6In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot compon...
CVE-2023-38018MEDIUM5.4IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user...
CVE-2023-40261MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails...
CVE-2023-33206MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails...
CVE-2023-28865MEDIUM6.6Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate...
CVE-2023-24064MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authoriz...
CVE-2023-24063MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authoriza...
CVE-2023-24062MEDIUM6.8Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate...
CVE-2023-7265MEDIUM6.2Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability ma...
CVE-2023-28806MEDIUM6.5An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-...
CVE-2023-40819MEDIUM6.1ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injec...
CVE-2023-31355MEDIUM6Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC s...
CVE-2023-28149MEDIUM6.1An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05...
CVE-2023-38001MEDIUM6.5IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malic...
CVE-2023-26289MEDIUM5.4IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST...
CVE-2023-26288MEDIUM5.5IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated use...
CVE-2023-52888MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Only free buffer VA that i...
CVE-2023-42943MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma ...
CVE-2023-42918MEDIUM6.3A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed proc...
CVE-2023-52887MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightl...
CVE-2023-49921MEDIUM6.5An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now