2023 CVE Vulnerabilities

31,213 CVEs published in 2023.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2023-4624LOW2.4Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
CVE-2023-0654LOW3.7Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the ev...
CVE-2023-38158LOW3.1Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-39061LOW3.5Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privilege...
CVE-2023-25647LOW3.3 There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app...
CVE-2023-32453LOW3.9 Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may po...
CVE-2023-39843LOW2.4Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via bri...
CVE-2023-39842LOW2.4Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned ...
CVE-2023-21278LOW3.3In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the c...
CVE-2023-21232LOW3.3In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. ...
CVE-2023-4304LOW2.7Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
CVE-2023-30700LOW3.3PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local ...
CVE-2023-30685LOW3.3Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mo...
CVE-2023-30684LOW3.3Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingC...
CVE-2023-30683LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without pe...
CVE-2023-30682LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API with...
CVE-2023-39341LOW3.3"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, wh...
CVE-2023-39342LOW3.6Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzo...
CVE-2023-39978LOW3.3ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
CVE-2023-38700LOW3.7matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such...
CVE-2023-3669LOW3.3A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimi...
CVE-2023-26979LOW3.1Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the...
CVE-2023-26442LOW3.2In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by th...
CVE-2023-26438LOW3.1External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, inv...
CVE-2023-4016LOW3.3Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now