2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22722MEDIUM6.1GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-...
CVE-2023-22500HIGH7.5GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to In...
CVE-2023-22486HIGH7.5cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29...
CVE-2023-22482HIGH8.8Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and p...
CVE-2023-22468MEDIUM5.4Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an...
CVE-2023-20928HIGH7.8In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local es...
CVE-2023-20925HIGH7.8In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. Thi...
CVE-2023-20924MEDIUM6.8In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo...
CVE-2023-20923MEDIUM5.5In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to...
CVE-2023-20922MEDIUM5.5In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea...
CVE-2023-20921HIGH7.3In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility ser...
CVE-2023-20920HIGH7.8In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local...
CVE-2023-20919HIGH7.8In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error i...
CVE-2023-20916HIGH7.8In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti...
CVE-2023-20915HIGH7.8In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without use...
CVE-2023-20913HIGH7.8In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into ena...
CVE-2023-20912HIGH7.8In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due ...
CVE-2023-20908MEDIUM5.5In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could...
CVE-2023-20905HIGH7.8In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2023-20904HIGH7.8In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent misma...
CVE-2023-0516HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit...
CVE-2023-0515HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Thi...
CVE-2023-0513MEDIUM5.4A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability a...
CVE-2023-0476MEDIUM6.5A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning i...
CVE-2023-0469MEDIUM5.5A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now