2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33014 | MEDIUM | 6.8 | 0.2% | Jan 2, 2024 | Information disclosure in Core services while processing a Diag command. |
| CVE-2023-26159 | MEDIUM | 6.1 | 0.8% | Jan 2, 2024 | Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper h... |
| CVE-2023-32891 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local... |
| CVE-2023-32885 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation... |
| CVE-2023-32884 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local esca... |
| CVE-2023-32883 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala... |
| CVE-2023-32882 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of ... |
| CVE-2023-32881 | MEDIUM | 4.4 | 0.1% | Jan 2, 2024 | In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information ... |
| CVE-2023-32880 | MEDIUM | 4.4 | 0.1% | Jan 2, 2024 | In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati... |
| CVE-2023-32879 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2023-32878 | MEDIUM | 4.4 | 0.1% | Jan 2, 2024 | In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati... |
| CVE-2023-32877 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2023-32876 | MEDIUM | 4.4 | 0.1% | Jan 2, 2024 | In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform... |
| CVE-2023-32875 | MEDIUM | 4.4 | 0.1% | Jan 2, 2024 | In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform... |
| CVE-2023-32872 | MEDIUM | 6.7 | 0.1% | Jan 2, 2024 | In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2023-32831 | MEDIUM | 5.5 | 0.2% | Jan 2, 2024 | In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local infor... |
| CVE-2023-6485 | MEDIUM | 5.4 | 0.5% | Jan 1, 2024 | The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which co... |
| CVE-2023-6037 | MEDIUM | 4.8 | 0.4% | Jan 1, 2024 | The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which c... |
| CVE-2023-6000 | MEDIUM | 6.1 | 2.0% | Jan 1, 2024 | The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and inje... |
| CVE-2023-6094 | MEDIUM | 5.3 | 0.2% | Dec 31, 2023 | A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability resu... |
| CVE-2023-6093 | MEDIUM | 6.1 | 0.3% | Dec 31, 2023 | A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vul... |
| CVE-2023-52284 | MEDIUM | 5.5 | 0.3% | Dec 31, 2023 | Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or co... |
| CVE-2023-52269 | MEDIUM | 4.8 | 0.4% | Dec 31, 2023 | MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain a... |
| CVE-2023-52265 | MEDIUM | 5.4 | 0.4% | Dec 30, 2023 | IDURAR (aka idurar-erp-crm) through 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in th... |
| CVE-2023-52264 | MEDIUM | 6.1 | 0.4% | Dec 30, 2023 | The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now