CVEs from 2023
Total
8,275
critical
critical 222
high
high 1,548
medium
medium 1,277
low
low 23
% Critical
2.7%
% with KEV
2.0%
% with exploit
2.0%
Top vendors
- redhat 120
- microsoft 76
- f5 43
- cisco 26
- automattic 19
- cbot 12
- brainstormforce 11
- gvectors 10
Top products
- office 29
- office_long_term_servicing_channel 15
- 365_apps 14
- openstack_platform 6
- codeready_linux_builder_for_ibm_z_systems_eus 6
- registrationmagic 6
- codeready_linux_builder_eus 6
- cbot_panel 6
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2023-52560 | high | — | 8.0 | 2y ago | Important: kernel-rt security and bug fix update | |
| CVE-2023-52775 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52683 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52615 | high | — | 8.0 | 2y ago | Important: kernel-rt security and bug fix update | |
| CVE-2023-52662 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52648 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52686 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52762 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52730 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52619 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52878 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-42843 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2023-52813 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52451 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-42956 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2023-52834 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-5841 | high | — | 8.0 | 2y ago | Important: openexr security update | |
| CVE-2023-52658 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-43010 | high | — | 8.0 | 2y ago | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. P… | |
| CVE-2023-52800 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52798 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52884 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52463 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-31315 | high | — | 8.0 | 2y ago | Important: linux-firmware security update | |
| CVE-2023-52771 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52880 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52651 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52796 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52864 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52471 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52847 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52764 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52530 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52803 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52845 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52623 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52777 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52653 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52809 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52638 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-52667 | high | — | 8.0 | 2y ago | Important: kernel-rt security and bug fix update | |
| CVE-2023-52626 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52700 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52669 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52675 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52877 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52781 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-52835 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-4727 | high | — | 8.0 | 2y ago | Important: pki-core security update | |
| CVE-2023-6597 | high | — | 8.0 | 2y ago | Important: python3.9 security update | |
| CVE-2023-20592 | high | — | 8.0 | 2y ago | Important: linux-firmware security update | |
| CVE-2023-5090 | high | — | 8.0 | 2y ago | Important: kernel security and bug fix update | |
| CVE-2023-54316 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: refscale: Fix uninitalized use of wait_queue_head_t Running the refscale test occasionally crashes the kernel with the following … | |
| CVE-2023-53547 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix sdma v4 sw fini error Fix sdma v4 sw fini error for sdma 4.2.2 to solve the following general protection fault [… | |
| CVE-2023-54302 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix data race on CQP completion stats CQP completion statistics is read lockesly in irdma_wait_event and irdma_check_… | |
| CVE-2023-42970 | high | — | 8.0 | 2y ago | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to … | |
| CVE-2023-53047 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix race condition in amdtee_open_session There is a potential race condition in amdtee_open_session that may lead t… | |
| CVE-2023-54242 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: block, bfq: Fix division by zero error on zero wsum When the weighted sum is zero the calculation of limit causes a division by z… | |
| CVE-2023-53612 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Simplify platform device handling Coretemp's platform driver is unconventional. All the real work is done globa… | |
| CVE-2023-53317 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix WARNING in mb_find_extent Syzbot found the following issue: EXT4-fs: Warning: mounting with data=journal disables dela… | |
| CVE-2023-52486 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-53823 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: block/rq_qos: protect rq_qos apis with a new lock commit 50e34d78815e ("block: disable the elevator int del_gendisk") move rq_qos… | |
| CVE-2023-54135 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() Check the write offset end bounds before using it as the offse… | |
| CVE-2023-53784 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm: bridge: dw_hdmi: fix connector access for scdc Commit 5d844091f237 ("drm/scdc-helper: Pimp SCDC debugs") changed the scdc in… | |
| CVE-2023-52470 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-53821 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix slab-use-after-free in decode_session6 When ipv6_vti device is set to the qdisc of the sfb type, the cb field of the… | |
| CVE-2023-53791 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: md: fix warning for holder mismatch from export_rdev() Commit a1d767191096 ("md: use mddev->external to select holder in export_r… | |
| CVE-2023-52832 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2023-53663 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Check instead of asserting on nested TSC scaling support Check for nested TSC scaling support on nested SVM VMRUN inst… | |
| CVE-2023-53496 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Use alternate source for socket to node data The UV code attempts to build a set of tables to allow it to do bid… | |
| CVE-2023-53661 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: bnxt: avoid overflow in bnxt_get_nvram_directory() The value of an arithmetic expression is subject of possible overflow due to a… | |
| CVE-2023-53652 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: vdpa: Add features attr to vdpa_nl_policy for nlattr length check The vdpa_nl_policy structure is used to validate the nlattr whe… | |
| CVE-2023-54016 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak in rx_desc and tx_desc Currently when ath12k_dp_cc_desc_init() is called we allocate memory to rx_d… | |
| CVE-2023-53585 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: bpf: reject unhashed sockets in bpf_sk_assign The semantics for bpf_sk_assign are as follows: sk = some_lookup_func() bp… | |
| CVE-2023-53649 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: perf trace: Really free the evsel->priv area In 3cb4d5e00e037c70 ("perf trace: Free syscall tp fields in evsel->priv") it only wa… | |
| CVE-2023-53645 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: bpf: Make bpf_refcount_acquire fallible for non-owning refs This patch fixes an incorrect assumption made in the original bpf_ref… | |
| CVE-2023-53632 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take RTNL lock when needed before calling xdp_set_features() Hold RTNL lock when calling xdp_set_features() with a reg… | |
| CVE-2023-53586 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix multiple LUN_RESET handling This fixes a bug where an initiator thinks a LUN_RESET has cleaned up running comma… | |
| CVE-2023-42756 | high | — | 8.0 | 2y ago | Important: kernel security, bug fix, and enhancement update | |
| CVE-2023-54120 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix race condition in hidp_session_thread There is a potential race condition in hidp_session_thread that may lead to … | |
| CVE-2023-53352 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: check null pointer before accessing when swapping Add a check to avoid null pointer dereference as below: [ 90.002283… | |
| CVE-2023-53354 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: skbuff: skb_segment, Call zero copy functions before using skbuff frags Commit bf5c25d60861 ("skbuff: in skb_segment, call zeroco… | |
| CVE-2023-53713 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: arm64: sme: Use STR P to clear FFR context field in streaming SVE mode The FFR is a predicate register which can vary between 16 … | |
| CVE-2023-39928 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2023-53280 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue System crash when qla2x00_start_sp(sp) returns error code EGAIN and wake_up… | |
| CVE-2023-53293 | high | — | 8.0 | 2y ago | RHSA-2024:2394: kernel security, bug fix, and enhancement update (Important) | |
| CVE-2023-53384 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: avoid possible NULL skb pointer dereference In 'mwifiex_handle_uap_rx_forward()', always check the value returned … | |
| CVE-2023-53490 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix disconnect vs accept race Despite commit 0ad529d9fd2b ("mptcp: fix possible divide by zero in recvmsg()"), the mptcp p… | |
| CVE-2023-53665 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: md: don't dereference mddev after export_rdev() Except for initial reference, mddev->kobject is referenced by rdev->kobject, and … | |
| CVE-2023-53709 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Handle race between rb_move_tail and rb_check_pages It seems a data race between ring_buffer writing and integrity c… | |
| CVE-2023-53751 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname TCP_Server_Info::hostname may be updated once or many times … | |
| CVE-2023-53016 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix possible deadlock in rfcomm_sk_state_change syzbot reports a possible deadlock in rfcomm_sk_state_change [1]. Whil… | |
| CVE-2023-54069 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow When we calculate the end position of ext4_free_extent, this position may… | |
| CVE-2023-53338 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: lwt: Fix return values of BPF xmit ops BPF encap ops can return different types of positive values, such like NET_RX_DROP, NET_XM… | |
| CVE-2023-45289 | high | — | 8.0 | 2y ago | Important: git-lfs security update | |
| CVE-2023-53046 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix race condition in hci_cmd_sync_clear There is a potential race condition in hci_cmd_sync_work and hci_cmd_sync_cle… | |
| CVE-2023-52999 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net: fix UaF in netns ops registration error path If net_assign_generic() fails, the current error path in ops_init() tries to cl… | |
| CVE-2023-53208 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Load L1's TSC multiplier based on L1 state, not L2 state When emulating nested VM-Exit, load L1's TSC multiplier if L1… | |
| CVE-2023-54096 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: soundwire: fix enumeration completion The soundwire subsystem uses two completion structures that allow drivers to wait for sound… | |
| CVE-2023-52529 | high | — | 8.0 | 2y ago | Important: kernel security, bug fix, and enhancement update |