2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21085HIGH8.8In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2023-21084MEDIUM6.7In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypto. This could lead t...
CVE-2023-21083HIGH7.8In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without showing a privacy i...
CVE-2023-21082MEDIUM5.5In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's c...
CVE-2023-21081HIGH7.8In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background ac...
CVE-2023-21080MEDIUM5.5In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This c...
CVE-2023-20967HIGH7.8In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check...
CVE-2023-20950HIGH7.8In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restr...
CVE-2023-20941MEDIUM6.6In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2023-20935MEDIUM5.5In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2023-20909MEDIUM5.5In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. T...
CVE-2023-20862MEDIUM6.3In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the...
CVE-2023-29922MEDIUM5.3PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.
CVE-2023-1900MEDIUM5.5A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an ...
CVE-2023-1587MEDIUM5.5Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue wa...
CVE-2023-1586MEDIUM4.7Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the resto...
CVE-2023-1585MEDIUM6.3Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quara...
CVE-2023-30614MEDIUM6.1Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is sus...
CVE-2023-30612MEDIUM4.9Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary op...
CVE-2023-30611MEDIUM5.3Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform....
CVE-2023-30610MEDIUM5.5aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` stru...
CVE-2023-22894MEDIUM4.9Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting ...
CVE-2023-22893HIGH7.5Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro...
CVE-2023-22621HIGH7.2Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra...
CVE-2023-29586MEDIUM5.5Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now