2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20917HIGH7.8In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the ...
CVE-2023-20911HIGH7.8In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due t...
CVE-2023-20910MEDIUM5.5In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustio...
CVE-2023-20906HIGH7.8In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after...
CVE-2023-28152CRITICAL9.8An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection...
CVE-2023-24625MEDIUM6.5Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object ...
CVE-2023-1177CRITICAL9.8Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
CVE-2023-1176LOW3.3Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
CVE-2023-27242MEDIUM5.4SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the ...
CVE-2023-1616MEDIUM5.4A vulnerability was found in XiaoBingBy TeaCMS up to 2.0.2. It has been classified as problematic. Affected is an unknow...
CVE-2023-28818MEDIUM5.3An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included uns...
CVE-2023-28686HIGH7.1Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via...
CVE-2023-28445CRITICAL9.8Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asyn...
CVE-2023-28443MEDIUM5.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_...
CVE-2023-28442MEDIUM5.3GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Pri...
CVE-2023-28441HIGH7.5smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will hav...
CVE-2023-27034CRITICAL9.8PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
CVE-2023-24787Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-24685. Reason: This record is a duplicate of CVE-2023-...
CVE-2023-24295HIGH7.8A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a ...
CVE-2023-28611CRITICAL9.8Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker ...
CVE-2023-28336MEDIUM4.3Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not...
CVE-2023-28335HIGH8.8The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
CVE-2023-28334MEDIUM4.3Authenticated users were able to enumerate other users' names via the learning plans page.
CVE-2023-28333CRITICAL9.8The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not ap...
CVE-2023-28332MEDIUM6.1If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presen...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now