2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21085 | HIGH | 8.8 | 0.2% | Apr 19, 2023 | In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2023-21084 | MEDIUM | 6.7 | 0.1% | Apr 19, 2023 | In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypto. This could lead t... |
| CVE-2023-21083 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without showing a privacy i... |
| CVE-2023-21082 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's c... |
| CVE-2023-21081 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background ac... |
| CVE-2023-21080 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This c... |
| CVE-2023-20967 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check... |
| CVE-2023-20950 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restr... |
| CVE-2023-20941 | MEDIUM | 6.6 | 0.2% | Apr 19, 2023 | In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. Th... |
| CVE-2023-20935 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2023-20909 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. T... |
| CVE-2023-20862 | MEDIUM | 6.3 | 0.6% | Apr 19, 2023 | In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the... |
| CVE-2023-29922 | MEDIUM | 5.3 | 3.0% | Apr 19, 2023 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. |
| CVE-2023-1900 | MEDIUM | 5.5 | 0.3% | Apr 19, 2023 | A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an ... |
| CVE-2023-1587 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue wa... |
| CVE-2023-1586 | MEDIUM | 4.7 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the resto... |
| CVE-2023-1585 | MEDIUM | 6.3 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quara... |
| CVE-2023-30614 | MEDIUM | 6.1 | 0.4% | Apr 19, 2023 | Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is sus... |
| CVE-2023-30612 | MEDIUM | 4.9 | 0.4% | Apr 19, 2023 | Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary op... |
| CVE-2023-30611 | MEDIUM | 5.3 | 0.4% | Apr 19, 2023 | Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.... |
| CVE-2023-30610 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` stru... |
| CVE-2023-22894 | MEDIUM | 4.9 | 1.7% | Apr 19, 2023 | Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting ... |
| CVE-2023-22893 | HIGH | 7.5 | 4.2% | Apr 19, 2023 | Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro... |
| CVE-2023-22621 | HIGH | 7.2 | 76.8% | Apr 19, 2023 | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra... |
| CVE-2023-29586 | MEDIUM | 5.5 | 0.3% | Apr 19, 2023 | Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now