2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42573 | MEDIUM | 5.5 | 0.2% | Dec 5, 2023 | PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to ac... |
| CVE-2023-42572 | MEDIUM | 5.5 | 0.3% | Dec 5, 2023 | Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensit... |
| CVE-2023-42571 | MEDIUM | 6.8 | 0.3% | Dec 5, 2023 | Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotel... |
| CVE-2023-42568 | MEDIUM | 4.4 | 0.2% | Dec 5, 2023 | Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access... |
| CVE-2023-42565 | MEDIUM | 6.7 | 0.2% | Dec 5, 2023 | Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell ... |
| CVE-2023-42564 | MEDIUM | 5.5 | 0.2% | Dec 5, 2023 | Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with sys... |
| CVE-2023-42561 | MEDIUM | 6.8 | 0.4% | Dec 5, 2023 | Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execu... |
| CVE-2023-42559 | MEDIUM | 5.2 | 0.3% | Dec 5, 2023 | Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass ... |
| CVE-2023-42557 | MEDIUM | 6.7 | 0.3% | Dec 5, 2023 | Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute a... |
| CVE-2023-42556 | MEDIUM | 5.5 | 0.2% | Dec 5, 2023 | Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive informati... |
| CVE-2023-33070 | MEDIUM | 5.5 | 0.1% | Dec 5, 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. |
| CVE-2023-28586 | MEDIUM | 6.5 | 0.1% | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
| CVE-2023-5808 | MEDIUM | 6.5 | 0.5% | Dec 5, 2023 | SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe... |
| CVE-2023-49292 | MEDIUM | 4.8 | 0.3% | Dec 5, 2023 | ecies is an Elliptic Curve Integrated Encryption Scheme for secp256k1 in Golang. If funcations Encapsulate(), Decapsulat... |
| CVE-2023-49290 | MEDIUM | 5.3 | 0.7% | Dec 5, 2023 | lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p... |
| CVE-2023-49289 | MEDIUM | 5.4 | 0.6% | Dec 5, 2023 | Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes th... |
| CVE-2023-49284 | MEDIUM | 6.6 | 0.5% | Dec 5, 2023 | fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certa... |
| CVE-2023-26943 | MEDIUM | 6.5 | 0.2% | Dec 5, 2023 | Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical p... |
| CVE-2023-26942 | MEDIUM | 6.5 | 0.2% | Dec 5, 2023 | Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical p... |
| CVE-2023-26941 | MEDIUM | 6.5 | 0.2% | Dec 5, 2023 | Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical p... |
| CVE-2023-49293 | MEDIUM | 6.1 | 1.0% | Dec 4, 2023 | Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml... |
| CVE-2023-49280 | MEDIUM | 6.5 | 0.9% | Dec 4, 2023 | XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the chang... |
| CVE-2023-45781 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ... |
| CVE-2023-40465 | MEDIUM | 5.5 | 0.2% | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be... |
| CVE-2023-40464 | MEDIUM | 6.8 | 0.3% | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now