2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-22293HIGH8.2Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to poten...
CVE-2023-48987HIGH7.5Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a re...
CVE-2023-44283HIGH7.8 In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4...
CVE-2023-38960HIGH7.3Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain pri...
CVE-2023-20587HIGH7.1Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leadin...
CVE-2023-6516HIGH7.5To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the data...
CVE-2023-5679HIGH7.5A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive re...
CVE-2023-5517HIGH7.5A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redir...
CVE-2023-4408HIGH7.5The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not ca...
CVE-2023-51440HIGH7.5A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7...
CVE-2023-50236HIGH7.8A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to ...
CVE-2023-49125HIGH7.8A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1...
CVE-2023-52431HIGH8.8The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism v...
CVE-2023-47218HIGH8.3An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-6294HIGH7.2The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could...
CVE-2023-52428HIGH7.5In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a larg...
CVE-2023-52427HIGH7.5In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_sample...
CVE-2023-50957HIGH7.2IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtain...
CVE-2023-45696HIGH7.5Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allow...
CVE-2023-45718HIGH7.5Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi...
CVE-2023-50349HIGH8.8Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy applica...
CVE-2023-50386HIGH8.8Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Fu...
CVE-2023-50298HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: ...
CVE-2023-50292HIGH7.5Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerabil...
CVE-2023-50291HIGH7.5Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now