2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25006 | HIGH | 7.8 | 0.2% | May 12, 2023 | A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which... |
| CVE-2023-25005 | HIGH | 7.8 | 0.2% | May 12, 2023 | A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 w... |
| CVE-2023-20880 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to th... |
| CVE-2023-20879 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privil... |
| CVE-2023-20878 | HIGH | 7.2 | 1.0% | May 12, 2023 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can ex... |
| CVE-2023-20877 | HIGH | 8.8 | 0.7% | May 12, 2023 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly priv... |
| CVE-2023-1096 | CRITICAL | 9.8 | 1.0% | May 12, 2023 | SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a rem... |
| CVE-2023-32306 | CRITICAL | 9.8 | 0.7% | May 12, 2023 | Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker ... |
| CVE-2023-32305 | HIGH | 8.8 | 0.7% | May 12, 2023 | aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing e... |
| CVE-2023-30247 | CRITICAL | 9.8 | 1.5% | May 12, 2023 | File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to exe... |
| CVE-2023-27863 | MEDIUM | 4.9 | 0.6% | May 12, 2023 | IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB cred... |
| CVE-2023-2458 | HIGH | 8.8 | 0.5% | May 12, 2023 | Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who con... |
| CVE-2023-2457 | HIGH | 8.8 | 0.4% | May 12, 2023 | Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attac... |
| CVE-2023-25927 | HIGH | 7.5 | 1.5% | May 12, 2023 | IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webse... |
| CVE-2023-31983 | CRITICAL | 9.8 | 24.9% | May 12, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr... |
| CVE-2023-28414 | MEDIUM | 4.8 | 0.4% | May 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ApexChat plugin <= 1.3.1 versions. |
| CVE-2023-25958 | MEDIUM | 4.8 | 0.4% | May 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <= 2.1.4 versions. |
| CVE-2023-25460 | MEDIUM | 4.8 | 0.4% | May 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodeSolz Easy Ad Manager plugin <= 1.0.0 versions. |
| CVE-2023-25428 | HIGH | 7.8 | 0.5% | May 12, 2023 | A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leadin... |
| CVE-2023-23810 | MEDIUM | 4.8 | 0.4% | May 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <= 1.5 versions. |
| CVE-2023-22685 | MEDIUM | 4.8 | 0.4% | May 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS f... |
| CVE-2023-31199 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user t... |
| CVE-2023-31197 | HIGH | 7.8 | 0.2% | May 12, 2023 | Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenti... |
| CVE-2023-30768 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with... |
| CVE-2023-30763 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentiall... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now