2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20945 | HIGH | 7.8 | 0.2% | Feb 28, 2023 | In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bo... |
| CVE-2023-20944 | HIGH | 7.8 | 0.2% | Feb 28, 2023 | In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. ... |
| CVE-2023-20943 | HIGH | 7.8 | 0.2% | Feb 28, 2023 | In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path... |
| CVE-2023-20940 | HIGH | 7.8 | 0.1% | Feb 28, 2023 | In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This... |
| CVE-2023-20939 | HIGH | 7.8 | 0.1% | Feb 28, 2023 | In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking... |
| CVE-2023-20938 | HIGH | 7.8 | 0.3% | Feb 28, 2023 | In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. T... |
| CVE-2023-20937 | HIGH | 7.8 | 0.2% | Feb 28, 2023 | In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. Thi... |
| CVE-2023-20934 | HIGH | 7.8 | 0.1% | Feb 28, 2023 | In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator... |
| CVE-2023-20933 | HIGH | 7.8 | 0.2% | Feb 28, 2023 | In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could le... |
| CVE-2023-20932 | LOW | 3.3 | 0.1% | Feb 28, 2023 | In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due t... |
| CVE-2023-20857 | MEDIUM | 6.8 | 0.9% | Feb 28, 2023 | VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted ... |
| CVE-2023-0511 | CRITICAL | 9.8 | 1.0% | Feb 28, 2023 | Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. Thi... |
| CVE-2023-0339 | CRITICAL | 9.8 | 1.0% | Feb 28, 2023 | Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This... |
| CVE-2023-26256 | HIGH | 7.5 | 11.6% | Feb 28, 2023 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2... |
| CVE-2023-26255 | HIGH | 7.5 | 47.9% | Feb 28, 2023 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2... |
| CVE-2023-25807 | MEDIUM | 5.4 | 0.5% | Feb 28, 2023 | DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved ... |
| CVE-2023-25266 | HIGH | 8.8 | 1.6% | Feb 28, 2023 | An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office dire... |
| CVE-2023-25265 | HIGH | 7.5 | 1.2% | Feb 28, 2023 | Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the fil... |
| CVE-2023-25264 | HIGH | 7.5 | 1.0% | Feb 28, 2023 | An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentic... |
| CVE-2023-23983 | MEDIUM | 5.4 | 0.2% | Feb 28, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to th... |
| CVE-2023-23865 | MEDIUM | 4.3 | 0.2% | Feb 28, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 lea... |
| CVE-2023-0461 | HIGH | 7.8 | 0.7% | Feb 28, 2023 | There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation... |
| CVE-2023-24419 | HIGH | 8.8 | 0.3% | Feb 28, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 version... |
| CVE-2023-23992 | MEDIUM | 4.3 | 0.3% | Feb 28, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete. |
| CVE-2023-1080 | MEDIUM | 6.1 | 1.3% | Feb 28, 2023 | The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in version... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now