2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-42573MEDIUM5.5PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to ac...
CVE-2023-42572MEDIUM5.5Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensit...
CVE-2023-42571MEDIUM6.8Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotel...
CVE-2023-42568MEDIUM4.4Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access...
CVE-2023-42565MEDIUM6.7Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell ...
CVE-2023-42564MEDIUM5.5Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with sys...
CVE-2023-42561MEDIUM6.8Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execu...
CVE-2023-42559MEDIUM5.2Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass ...
CVE-2023-42557MEDIUM6.7Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute a...
CVE-2023-42556MEDIUM5.5Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive informati...
CVE-2023-33070MEDIUM5.5Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
CVE-2023-28586MEDIUM6.5Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-5808MEDIUM6.5SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe...
CVE-2023-49292MEDIUM4.8ecies is an Elliptic Curve Integrated Encryption Scheme for secp256k1 in Golang. If funcations Encapsulate(), Decapsulat...
CVE-2023-49290MEDIUM5.3lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p...
CVE-2023-49289MEDIUM5.4Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes th...
CVE-2023-49284MEDIUM6.6fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certa...
CVE-2023-26943MEDIUM6.5Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical p...
CVE-2023-26942MEDIUM6.5Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical p...
CVE-2023-26941MEDIUM6.5Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical p...
CVE-2023-49293MEDIUM6.1Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml...
CVE-2023-49280MEDIUM6.5XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the chang...
CVE-2023-45781MEDIUM5.5In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ...
CVE-2023-40465MEDIUM5.5 Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be...
CVE-2023-40464MEDIUM6.8 Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now