2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20945HIGH7.8In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bo...
CVE-2023-20944HIGH7.8In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. ...
CVE-2023-20943HIGH7.8In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path...
CVE-2023-20940HIGH7.8In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This...
CVE-2023-20939HIGH7.8In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking...
CVE-2023-20938HIGH7.8In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. T...
CVE-2023-20937HIGH7.8In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. Thi...
CVE-2023-20934HIGH7.8In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator...
CVE-2023-20933HIGH7.8In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could le...
CVE-2023-20932LOW3.3In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due t...
CVE-2023-20857MEDIUM6.8VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted ...
CVE-2023-0511CRITICAL9.8Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. Thi...
CVE-2023-0339CRITICAL9.8Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This...
CVE-2023-26256HIGH7.5An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2...
CVE-2023-26255HIGH7.5An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2...
CVE-2023-25807MEDIUM5.4DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved ...
CVE-2023-25266HIGH8.8An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office dire...
CVE-2023-25265HIGH7.5Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the fil...
CVE-2023-25264HIGH7.5An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentic...
CVE-2023-23983MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to th...
CVE-2023-23865MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 lea...
CVE-2023-0461HIGH7.8There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation...
CVE-2023-24419HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 version...
CVE-2023-23992MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.
CVE-2023-1080MEDIUM6.1The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in version...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now