2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-28777HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDas...
CVE-2023-25047HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-25045HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-5099HIGH8.8The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in...
CVE-2023-38994HIGH7.8The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaint...
CVE-2023-45996HIGH8.8SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker ...
CVE-2023-45899HIGH7.5An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attack...
CVE-2023-46129HIGH7.5NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise,...
CVE-2023-46478HIGH8.8An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data ...
CVE-2023-45672HIGH7.5Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerabilit...
CVE-2023-45956HIGH7.5An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveW...
CVE-2023-42323HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code vi...
CVE-2023-42803HIGH8.8BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestri...
CVE-2023-41891HIGH8.8FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior...
CVE-2023-47101HIGH7.8The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalati...
CVE-2023-45780HIGH7.3In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to lo...
CVE-2023-21398HIGH7.8In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to ...
CVE-2023-21397HIGH7.8In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to loc...
CVE-2023-21396HIGH7.8In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to...
CVE-2023-21393HIGH7.8In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to lo...
CVE-2023-21392HIGH8.8In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of ...
CVE-2023-21391HIGH7.5In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could ...
CVE-2023-21390HIGH7.8In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to l...
CVE-2023-21389HIGH7.8In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead...
CVE-2023-21388HIGH7.8In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalati...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now