2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40461MEDIUM4.8 The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileg...
CVE-2023-40460MEDIUM5.4 The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which c...
CVE-2023-40098MEDIUM5.5In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user...
CVE-2023-40092MEDIUM5.5In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confu...
CVE-2023-40090MEDIUM6.5In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel info...
CVE-2023-40083MEDIUM5.5In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ...
CVE-2023-40081MEDIUM5.5In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to ...
CVE-2023-40076MEDIUM5.5In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due t...
CVE-2023-40075MEDIUM5.5In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a mi...
CVE-2023-40074MEDIUM5.5In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional...
CVE-2023-40073MEDIUM5.5In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to ...
CVE-2023-35668MEDIUM5.5In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy....
CVE-2023-24050MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code ...
CVE-2023-24047MEDIUM6.8An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain esca...
CVE-2023-24046MEDIUM6.8An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a ...
CVE-2023-5990MEDIUM6.5The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not ...
CVE-2023-5979MEDIUM6.5The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin p...
CVE-2023-5951MEDIUM6.1The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back ...
CVE-2023-5884MEDIUM6.5The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an u...
CVE-2023-5874MEDIUM4.8The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5809MEDIUM4.8The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5210MEDIUM6.1The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2023-5141MEDIUM6.1The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count paramete...
CVE-2023-5137MEDIUM4.8The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which ...
CVE-2023-5105MEDIUM6.5The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now