2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40104 | HIGH | 7.5 | 0.3% | Feb 15, 2024 | In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This... |
| CVE-2023-40100 | HIGH | 7.8 | 0.1% | Feb 15, 2024 | In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could... |
| CVE-2023-6255 | HIGH | 7.5 | 0.4% | Feb 15, 2024 | Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive ... |
| CVE-2023-4993 | HIGH | 7.5 | 0.4% | Feb 15, 2024 | Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data... |
| CVE-2023-45581 | HIGH | 7.2 | 0.8% | Feb 15, 2024 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and befo... |
| CVE-2023-4539 | HIGH | 7.5 | 0.5% | Feb 15, 2024 | Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacke... |
| CVE-2023-4537 | HIGH | 7.4 | 0.6% | Feb 15, 2024 | Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unenc... |
| CVE-2023-51787 | HIGH | 7.5 | 0.5% | Feb 15, 2024 | An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exi... |
| CVE-2023-6138 | HIGH | 7.9 | 0.2% | Feb 14, 2024 | A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might al... |
| CVE-2023-50927 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger o... |
| CVE-2023-50926 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can... |
| CVE-2023-48229 | HIGH | 7.6 | 0.4% | Feb 14, 2024 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write ex... |
| CVE-2023-6409 | HIGH | 7.7 | 0.2% | Feb 14, 2024 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file prot... |
| CVE-2023-6408 | HIGH | 8.1 | 0.3% | Feb 14, 2024 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists ... |
| CVE-2023-27975 | HIGH | 7.1 | 0.1% | Feb 14, 2024 | CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project ... |
| CVE-2023-50868 | HIGH | 7.5 | 81.7% | Feb 14, 2024 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote atta... |
| CVE-2023-50387 | HIGH | 7.5 | 100.0% | Feb 14, 2024 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to c... |
| CVE-2023-5123 | HIGH | 8 | 0.8% | Feb 14, 2024 | The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maint... |
| CVE-2023-46186 | HIGH | 7.5 | 0.6% | Feb 14, 2024 | IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using for... |
| CVE-2023-41231 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticat... |
| CVE-2023-41091 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user t... |
| CVE-2023-40161 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user ... |
| CVE-2023-40156 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to... |
| CVE-2023-40154 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged us... |
| CVE-2023-39432 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now