2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25006HIGH7.8A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which...
CVE-2023-25005HIGH7.8A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 w...
CVE-2023-20880MEDIUM6.7VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to th...
CVE-2023-20879MEDIUM6.7VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privil...
CVE-2023-20878HIGH7.2VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can ex...
CVE-2023-20877HIGH8.8VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly priv...
CVE-2023-1096CRITICAL9.8SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a rem...
CVE-2023-32306CRITICAL9.8Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker ...
CVE-2023-32305HIGH8.8aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing e...
CVE-2023-30247CRITICAL9.8File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to exe...
CVE-2023-27863MEDIUM4.9IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB cred...
CVE-2023-2458HIGH8.8Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who con...
CVE-2023-2457HIGH8.8Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attac...
CVE-2023-25927HIGH7.5IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webse...
CVE-2023-31983CRITICAL9.8A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr...
CVE-2023-28414MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ApexChat plugin <= 1.3.1 versions.
CVE-2023-25958MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <= 2.1.4 versions.
CVE-2023-25460MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodeSolz Easy Ad Manager plugin <= 1.0.0 versions.
CVE-2023-25428HIGH7.8A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leadin...
CVE-2023-23810MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <= 1.5 versions.
CVE-2023-22685MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS f...
CVE-2023-31199MEDIUM6.7Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user t...
CVE-2023-31197HIGH7.8Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenti...
CVE-2023-30768MEDIUM6.7Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with...
CVE-2023-30763MEDIUM6.7Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentiall...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now