2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20578 | MEDIUM | 6.4 | 0.1% | Aug 13, 2024 | A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or U... |
| CVE-2023-20510 | MEDIUM | 6 | 0.1% | Aug 13, 2024 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ... |
| CVE-2023-20509 | MEDIUM | 5.2 | 0.1% | Aug 13, 2024 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DR... |
| CVE-2023-41884 | MEDIUM | 6.5 | 0.5% | Aug 12, 2024 | ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes ... |
| CVE-2023-50810 | MEDIUM | 6 | 0.8% | Aug 12, 2024 | In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot compon... |
| CVE-2023-38018 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user... |
| CVE-2023-40261 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails... |
| CVE-2023-33206 | MEDIUM | 6.8 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails... |
| CVE-2023-28865 | MEDIUM | 6.6 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate... |
| CVE-2023-24064 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authoriz... |
| CVE-2023-24063 | MEDIUM | 6.8 | 0.3% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authoriza... |
| CVE-2023-24062 | MEDIUM | 6.8 | 0.4% | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate... |
| CVE-2023-7265 | MEDIUM | 6.2 | 0.1% | Aug 8, 2024 | Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability ma... |
| CVE-2023-28806 | MEDIUM | 6.5 | 0.2% | Aug 6, 2024 | An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-... |
| CVE-2023-40819 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injec... |
| CVE-2023-31355 | MEDIUM | 6 | 0.4% | Aug 5, 2024 | Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC s... |
| CVE-2023-28149 | MEDIUM | 6.1 | 0.1% | Jul 31, 2024 | An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05... |
| CVE-2023-38001 | MEDIUM | 6.5 | 0.2% | Jul 30, 2024 | IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... |
| CVE-2023-26289 | MEDIUM | 5.4 | 0.3% | Jul 30, 2024 | IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST... |
| CVE-2023-26288 | MEDIUM | 5.5 | 0.2% | Jul 30, 2024 | IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated use... |
| CVE-2023-52888 | MEDIUM | 5.5 | 0.2% | Jul 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Only free buffer VA that i... |
| CVE-2023-42943 | MEDIUM | 5.5 | 0.2% | Jul 29, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma ... |
| CVE-2023-42918 | MEDIUM | 6.3 | 0.2% | Jul 29, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed proc... |
| CVE-2023-52887 | MEDIUM | 5.5 | 0.2% | Jul 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightl... |
| CVE-2023-49921 | MEDIUM | 6.5 | 0.5% | Jul 26, 2024 | An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now