2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40104HIGH7.5In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This...
CVE-2023-40100HIGH7.8In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could...
CVE-2023-6255HIGH7.5Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive ...
CVE-2023-4993HIGH7.5Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data...
CVE-2023-45581HIGH7.2An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and befo...
CVE-2023-4539HIGH7.5Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacke...
CVE-2023-4537HIGH7.4Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unenc...
CVE-2023-51787HIGH7.5An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exi...
CVE-2023-6138HIGH7.9A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might al...
CVE-2023-50927HIGH7.5Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger o...
CVE-2023-50926HIGH7.5Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can...
CVE-2023-48229HIGH7.6Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write ex...
CVE-2023-6409HIGH7.7 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file prot...
CVE-2023-6408HIGH8.1 CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists ...
CVE-2023-27975HIGH7.1 CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project ...
CVE-2023-50868HIGH7.5The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote atta...
CVE-2023-50387HIGH7.5Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to c...
CVE-2023-5123HIGH8The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maint...
CVE-2023-46186HIGH7.5IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using for...
CVE-2023-41231HIGH7.8Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticat...
CVE-2023-41091HIGH7.8Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user t...
CVE-2023-40161HIGH7.8Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user ...
CVE-2023-40156HIGH7.8Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to...
CVE-2023-40154HIGH7.8Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged us...
CVE-2023-39432HIGH7.8Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now