2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25522 | HIGH | 7.8 | 0.2% | Jul 4, 2023 | NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by p... |
| CVE-2023-25521 | HIGH | 7.8 | 0.1% | Jul 4, 2023 | NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privi... |
| CVE-2023-25517 | HIGH | 7.1 | 0.2% | Jul 4, 2023 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to... |
| CVE-2023-25516 | HIGH | 7.1 | 0.2% | Jul 4, 2023 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can c... |
| CVE-2023-22906 | HIGH | 8.8 | 0.7% | Jul 4, 2023 | Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password. |
| CVE-2023-3395 | MEDIUM | 6.5 | 0.3% | Jul 3, 2023 | All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with acc... |
| CVE-2023-36611 | MEDIUM | 6.5 | 0.4% | Jul 3, 2023 | The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could all... |
| CVE-2023-36610 | MEDIUM | 5.9 | 0.4% | Jul 3, 2023 | The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate ... |
| CVE-2023-36377 | HIGH | 7.8 | 0.3% | Jul 3, 2023 | Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary cod... |
| CVE-2023-36291 | MEDIUM | 6.1 | 0.4% | Jul 3, 2023 | Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_c... |
| CVE-2023-36262 | — | — | — | Jul 3, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-36258 | CRITICAL | 9.8 | 1.0% | Jul 3, 2023 | An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex... |
| CVE-2023-36223 | MEDIUM | 5.4 | 0.7% | Jul 3, 2023 | Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary... |
| CVE-2023-36222 | MEDIUM | 5.4 | 0.7% | Jul 3, 2023 | Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary... |
| CVE-2023-36183 | HIGH | 7.8 | 0.4% | Jul 3, 2023 | Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain ... |
| CVE-2023-36162 | HIGH | 8.8 | 0.4% | Jul 3, 2023 | Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the... |
| CVE-2023-2728 | MEDIUM | 6.5 | 2.2% | Jul 3, 2023 | Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission... |
| CVE-2023-2727 | MEDIUM | 6.5 | 1.1% | Jul 3, 2023 | Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral conta... |
| CVE-2023-37378 | MEDIUM | 5.3 | 0.7% | Jul 3, 2023 | Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. |
| CVE-2023-36609 | HIGH | 7.2 | 0.6% | Jul 3, 2023 | The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker cou... |
| CVE-2023-36608 | MEDIUM | 6.5 | 0.2% | Jul 3, 2023 | The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm. |
| CVE-2023-36819 | MEDIUM | 6.5 | 0.7% | Jul 3, 2023 | Knowage is the professional open source suite for modern business analytics over traditional sources and big data system... |
| CVE-2023-36817 | CRITICAL | 9.1 | 0.5% | Jul 3, 2023 | `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f... |
| CVE-2023-36815 | HIGH | 8.1 | 0.5% | Jul 3, 2023 | Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is... |
| CVE-2023-3497 | MEDIUM | 4.6 | 0.1% | Jul 3, 2023 | Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now