2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40097HIGH7.8In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation...
CVE-2023-40096HIGH7.8In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the backgroun...
CVE-2023-40095HIGH7.8In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due t...
CVE-2023-40094HIGH7.8In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permiss...
CVE-2023-40091HIGH7.8In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead ...
CVE-2023-40089HIGH7.8In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credent...
CVE-2023-40088HIGH8.8In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption du...
CVE-2023-40087HIGH8.8In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds chec...
CVE-2023-40084HIGH7.8In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local es...
CVE-2023-40080HIGH7.8In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This ...
CVE-2023-40079HIGH7.8In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions b...
CVE-2023-40077HIGH8.1In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to rem...
CVE-2023-24048HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control...
CVE-2023-21227HIGH7.5In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lea...
CVE-2023-6063HIGH7.5The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in ...
CVE-2023-5953HIGH8.8The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have au...
CVE-2023-5762HIGH8.8The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows t...
CVE-2023-5108HIGH7.2The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin...
CVE-2023-47633HIGH7.5Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serve...
CVE-2023-48966HIGH8.8An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to...
CVE-2023-48965HIGH8.8An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a cra...
CVE-2023-41613HIGH7.8EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
CVE-2023-48863HIGH7.5SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attac...
CVE-2023-32804HIGH7.8Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd...
CVE-2023-6481HIGH7.5A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now