2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43758HIGH8.7Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enabl...
CVE-2023-34440HIGH8.7Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl...
CVE-2023-32277MEDIUM6.1Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticat...
CVE-2023-31276HIGH8.4Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R...
CVE-2023-29164HIGH7.3Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) S...
CVE-2023-49780MEDIUM6.1Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on ...
CVE-2023-31345HIGH7.5Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ...
CVE-2023-20508MEDIUM5Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory locat...
CVE-2023-31352MEDIUM6A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in los...
CVE-2023-31343HIGH7.5Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ...
CVE-2023-31342HIGH7.5Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ...
CVE-2023-31331LOW3Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initialization...
CVE-2023-20582MEDIUM5.3Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table...
CVE-2023-20581LOW2.5Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss...
CVE-2023-20515MEDIUM5.7Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory,...
CVE-2023-20507LOW2.3An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resultin...
CVE-2023-31361HIGH7.3A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attac...
CVE-2023-31360HIGH7.3Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation dir...
CVE-2023-40721MEDIUM6.7A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged atta...
CVE-2023-37482MEDIUM6.9The login functionality of the web server in affected devices does not normalize the response times of login attempts. A...
CVE-2023-7182Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6819Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6167Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6060Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-5513Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now