2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40461 | MEDIUM | 4.8 | 0.5% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileg... |
| CVE-2023-40460 | MEDIUM | 5.4 | 0.5% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which c... |
| CVE-2023-40098 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user... |
| CVE-2023-40092 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confu... |
| CVE-2023-40090 | MEDIUM | 6.5 | 0.5% | Dec 4, 2023 | In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel info... |
| CVE-2023-40083 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ... |
| CVE-2023-40081 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to ... |
| CVE-2023-40076 | MEDIUM | 5.5 | 2.3% | Dec 4, 2023 | In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due t... |
| CVE-2023-40075 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a mi... |
| CVE-2023-40074 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional... |
| CVE-2023-40073 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to ... |
| CVE-2023-35668 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy.... |
| CVE-2023-24050 | MEDIUM | 5.4 | 0.4% | Dec 4, 2023 | Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code ... |
| CVE-2023-24047 | MEDIUM | 6.8 | 0.4% | Dec 4, 2023 | An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain esca... |
| CVE-2023-24046 | MEDIUM | 6.8 | 0.6% | Dec 4, 2023 | An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a ... |
| CVE-2023-5990 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not ... |
| CVE-2023-5979 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin p... |
| CVE-2023-5951 | MEDIUM | 6.1 | 0.5% | Dec 4, 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2023-5884 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an u... |
| CVE-2023-5874 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5809 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5210 | MEDIUM | 6.1 | 0.4% | Dec 4, 2023 | The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2023-5141 | MEDIUM | 6.1 | 0.4% | Dec 4, 2023 | The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count paramete... |
| CVE-2023-5137 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which ... |
| CVE-2023-5105 | MEDIUM | 6.5 | 1.0% | Dec 4, 2023 | The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now