2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2191MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.
CVE-2023-2166MEDIUM5.5A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may no...
CVE-2023-28328MEDIUM5.5A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel...
CVE-2023-28327MEDIUM5.5A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Ke...
CVE-2023-23451CRITICAL9.8The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmwar...
CVE-2023-1382MEDIUM4.7A data race flaw was found in the Linux kernel, between where con is allocated and con->sock is set. This issue leads to...
CVE-2023-30797HIGH7.5Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficie...
CVE-2023-2162MEDIUM5.5A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-componen...
CVE-2023-28124MEDIUM5.5Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with ...
CVE-2023-28123MEDIUM5.5A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VP...
CVE-2023-28122HIGH7.8A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a mali...
CVE-2023-21100HIGH7.8In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local...
CVE-2023-21099HIGH7.8In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the backg...
CVE-2023-21098HIGH7.8In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Setti...
CVE-2023-21097HIGH7.8In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This cou...
CVE-2023-21096CRITICAL9.8In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution wi...
CVE-2023-21094HIGH7.8In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due ...
CVE-2023-21093HIGH7.8In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other appl...
CVE-2023-21092HIGH7.8In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver usi...
CVE-2023-21091MEDIUM5.5In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a miss...
CVE-2023-21090MEDIUM5In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could...
CVE-2023-21089HIGH7.8In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive whi...
CVE-2023-21088HIGH7.8In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch ...
CVE-2023-21087MEDIUM5.5In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to lo...
CVE-2023-21086HIGH7.8In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC f...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now