2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43758 | HIGH | 8.7 | 0.3% | Feb 12, 2025 | Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enabl... |
| CVE-2023-34440 | HIGH | 8.7 | 0.2% | Feb 12, 2025 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl... |
| CVE-2023-32277 | MEDIUM | 6.1 | 0.2% | Feb 12, 2025 | Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticat... |
| CVE-2023-31276 | HIGH | 8.4 | 0.2% | Feb 12, 2025 | Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R... |
| CVE-2023-29164 | HIGH | 7.3 | 0.2% | Feb 12, 2025 | Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) S... |
| CVE-2023-49780 | MEDIUM | 6.1 | 0.3% | Feb 12, 2025 | Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on ... |
| CVE-2023-31345 | HIGH | 7.5 | 0.2% | Feb 12, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ... |
| CVE-2023-20508 | MEDIUM | 5 | 0.1% | Feb 12, 2025 | Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory locat... |
| CVE-2023-31352 | MEDIUM | 6 | 0.2% | Feb 11, 2025 | A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in los... |
| CVE-2023-31343 | HIGH | 7.5 | 0.2% | Feb 11, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ... |
| CVE-2023-31342 | HIGH | 7.5 | 0.2% | Feb 11, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to ... |
| CVE-2023-31331 | LOW | 3 | 0.1% | Feb 11, 2025 | Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initialization... |
| CVE-2023-20582 | MEDIUM | 5.3 | 0.2% | Feb 11, 2025 | Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table... |
| CVE-2023-20581 | LOW | 2.5 | 0.2% | Feb 11, 2025 | Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss... |
| CVE-2023-20515 | MEDIUM | 5.7 | 0.2% | Feb 11, 2025 | Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory,... |
| CVE-2023-20507 | LOW | 2.3 | 0.1% | Feb 11, 2025 | An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resultin... |
| CVE-2023-31361 | HIGH | 7.3 | 0.2% | Feb 11, 2025 | A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attac... |
| CVE-2023-31360 | HIGH | 7.3 | 0.2% | Feb 11, 2025 | Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation dir... |
| CVE-2023-40721 | MEDIUM | 6.7 | 0.2% | Feb 11, 2025 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged atta... |
| CVE-2023-37482 | MEDIUM | 6.9 | 0.5% | Feb 11, 2025 | The login functionality of the web server in affected devices does not normalize the response times of login attempts. A... |
| CVE-2023-7182 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-6819 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-6167 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-6060 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-5513 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now