2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22722 | MEDIUM | 6.1 | 0.6% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-... |
| CVE-2023-22500 | HIGH | 7.5 | 0.8% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to In... |
| CVE-2023-22486 | HIGH | 7.5 | 1.1% | Jan 26, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29... |
| CVE-2023-22482 | HIGH | 8.8 | 0.9% | Jan 26, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and p... |
| CVE-2023-22468 | MEDIUM | 5.4 | 0.5% | Jan 26, 2023 | Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an... |
| CVE-2023-20928 | HIGH | 7.8 | 0.2% | Jan 26, 2023 | In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local es... |
| CVE-2023-20925 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. Thi... |
| CVE-2023-20924 | MEDIUM | 6.8 | 0.2% | Jan 26, 2023 | In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo... |
| CVE-2023-20923 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to... |
| CVE-2023-20922 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea... |
| CVE-2023-20921 | HIGH | 7.3 | 0.3% | Jan 26, 2023 | In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility ser... |
| CVE-2023-20920 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local... |
| CVE-2023-20919 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error i... |
| CVE-2023-20916 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti... |
| CVE-2023-20915 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without use... |
| CVE-2023-20913 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into ena... |
| CVE-2023-20912 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due ... |
| CVE-2023-20908 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could... |
| CVE-2023-20905 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. Th... |
| CVE-2023-20904 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent misma... |
| CVE-2023-0516 | HIGH | 7.2 | 1.0% | Jan 26, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit... |
| CVE-2023-0515 | HIGH | 7.2 | 1.0% | Jan 26, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Thi... |
| CVE-2023-0513 | MEDIUM | 5.4 | 0.7% | Jan 26, 2023 | A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability a... |
| CVE-2023-0476 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning i... |
| CVE-2023-0469 | MEDIUM | 5.5 | 0.3% | Jan 26, 2023 | A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now