2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2023-38158LOW3.1Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-39061LOW3.5Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privilege...
CVE-2023-25647LOW3.3 There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app...
CVE-2023-32453LOW3.9 Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may po...
CVE-2023-39843LOW2.4Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via bri...
CVE-2023-39842LOW2.4Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned ...
CVE-2023-21278LOW3.3In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the c...
CVE-2023-21232LOW3.3In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. ...
CVE-2023-4304LOW2.7Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
CVE-2023-30700LOW3.3PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local ...
CVE-2023-30685LOW3.3Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mo...
CVE-2023-30684LOW3.3Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingC...
CVE-2023-30683LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without pe...
CVE-2023-30682LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API with...
CVE-2023-39341LOW3.3"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, wh...
CVE-2023-39342LOW3.6Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzo...
CVE-2023-39978LOW3.3ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
CVE-2023-38700LOW3.7matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such...
CVE-2023-3669LOW3.3A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimi...
CVE-2023-26979LOW3.1Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the...
CVE-2023-26442LOW3.2In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by th...
CVE-2023-26438LOW3.1External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, inv...
CVE-2023-4016LOW3.3Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability t...
CVE-2023-37904LOW3.1Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-37900LOW2.7Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now