2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35368HIGH8.8Microsoft Exchange Remote Code Execution Vulnerability
CVE-2023-35359HIGH7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-2230Rejected reason: Accidental Assignment
CVE-2023-29330HIGH8.8Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-29328HIGH8.8Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-21709CRITICAL9.8Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2023-20589MEDIUM6.8 An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault ...
CVE-2023-20588MEDIUM5.5 A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidenti...
CVE-2023-20586CRITICAL9.8 A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privile...
CVE-2023-20569MEDIUM4.7 A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction...
CVE-2023-20562HIGH7.8 Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user...
CVE-2023-20561MEDIUM5.5 Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated ...
CVE-2023-20556MEDIUM5.5 Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated us...
CVE-2023-20555HIGH7.8Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbi...
CVE-2023-39532CRITICAL9.8SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prio...
CVE-2023-37646HIGH7.8An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory trave...
CVE-2023-3522CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal ...
CVE-2023-3386CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tra...
CVE-2023-38773HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp...
CVE-2023-38771HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp...
CVE-2023-38770HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group ...
CVE-2023-38769HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the search...
CVE-2023-38768HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the Proper...
CVE-2023-38767HIGH7.5SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value...
CVE-2023-38766MEDIUM5.4Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now