2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22293 | HIGH | 8.2 | 0.2% | Feb 14, 2024 | Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to poten... |
| CVE-2023-48987 | HIGH | 7.5 | 1.0% | Feb 14, 2024 | Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a re... |
| CVE-2023-44283 | HIGH | 7.8 | 0.2% | Feb 14, 2024 | In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4... |
| CVE-2023-38960 | HIGH | 7.3 | 0.3% | Feb 13, 2024 | Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain pri... |
| CVE-2023-20587 | HIGH | 7.1 | 0.2% | Feb 13, 2024 | Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leadin... |
| CVE-2023-6516 | HIGH | 7.5 | 1.1% | Feb 13, 2024 | To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the data... |
| CVE-2023-5679 | HIGH | 7.5 | 1.2% | Feb 13, 2024 | A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive re... |
| CVE-2023-5517 | HIGH | 7.5 | 1.2% | Feb 13, 2024 | A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redir... |
| CVE-2023-4408 | HIGH | 7.5 | 1.3% | Feb 13, 2024 | The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not ca... |
| CVE-2023-51440 | HIGH | 7.5 | 0.6% | Feb 13, 2024 | A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7... |
| CVE-2023-50236 | HIGH | 7.8 | 0.1% | Feb 13, 2024 | A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to ... |
| CVE-2023-49125 | HIGH | 7.8 | 0.2% | Feb 13, 2024 | A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1... |
| CVE-2023-52431 | HIGH | 8.8 | 0.2% | Feb 13, 2024 | The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism v... |
| CVE-2023-47218 | HIGH | 8.3 | 89.2% | Feb 13, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-6294 | HIGH | 7.2 | 0.8% | Feb 12, 2024 | The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could... |
| CVE-2023-52428 | HIGH | 7.5 | 0.8% | Feb 11, 2024 | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a larg... |
| CVE-2023-52427 | HIGH | 7.5 | 0.6% | Feb 11, 2024 | In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_sample... |
| CVE-2023-50957 | HIGH | 7.2 | 0.4% | Feb 10, 2024 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtain... |
| CVE-2023-45696 | HIGH | 7.5 | 0.4% | Feb 10, 2024 | Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allow... |
| CVE-2023-45718 | HIGH | 7.5 | 0.4% | Feb 9, 2024 | Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi... |
| CVE-2023-50349 | HIGH | 8.8 | 0.2% | Feb 9, 2024 | Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy applica... |
| CVE-2023-50386 | HIGH | 8.8 | 83.8% | Feb 9, 2024 | Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Fu... |
| CVE-2023-50298 | HIGH | 7.5 | 1.6% | Feb 9, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: ... |
| CVE-2023-50292 | HIGH | 7.5 | 3.0% | Feb 9, 2024 | Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerabil... |
| CVE-2023-50291 | HIGH | 7.5 | 3.3% | Feb 9, 2024 | Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now