2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25522HIGH7.8 NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by p...
CVE-2023-25521HIGH7.8 NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privi...
CVE-2023-25517HIGH7.1 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to...
CVE-2023-25516HIGH7.1 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can c...
CVE-2023-22906HIGH8.8Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
CVE-2023-3395MEDIUM6.5 ​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with acc...
CVE-2023-36611MEDIUM6.5 The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could all...
CVE-2023-36610MEDIUM5.9 ​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate ...
CVE-2023-36377HIGH7.8Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary cod...
CVE-2023-36291MEDIUM6.1Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_c...
CVE-2023-36262Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36258CRITICAL9.8An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex...
CVE-2023-36223MEDIUM5.4Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary...
CVE-2023-36222MEDIUM5.4Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary...
CVE-2023-36183HIGH7.8Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain ...
CVE-2023-36162HIGH8.8Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the...
CVE-2023-2728MEDIUM6.5Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission...
CVE-2023-2727MEDIUM6.5Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral conta...
CVE-2023-37378MEDIUM5.3Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
CVE-2023-36609HIGH7.2 The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker cou...
CVE-2023-36608MEDIUM6.5 The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
CVE-2023-36819MEDIUM6.5Knowage is the professional open source suite for modern business analytics over traditional sources and big data system...
CVE-2023-36817CRITICAL9.1`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f...
CVE-2023-36815HIGH8.1Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is...
CVE-2023-3497MEDIUM4.6Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now