2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42539 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows loc... |
| CVE-2023-42534 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to rea... |
| CVE-2023-42533 | MEDIUM | 6.8 | 0.4% | Nov 7, 2023 | Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execut... |
| CVE-2023-42527 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local a... |
| CVE-2023-41723 | MEDIUM | 4.3 | 12.3% | Nov 7, 2023 | A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: ... |
| CVE-2023-38549 | MEDIUM | 5.4 | 19.1% | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acqui... |
| CVE-2023-38548 | MEDIUM | 4.3 | 11.8% | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acqui... |
| CVE-2023-47102 | MEDIUM | 5.3 | 0.6% | Nov 7, 2023 | UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a usernam... |
| CVE-2023-28569 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28568 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information disclosure in WLAN HAL when reception status handler is called. |
| CVE-2023-28566 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information disclosure in WLAN HAL while handling the WMI state info command. |
| CVE-2023-28563 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. |
| CVE-2023-28554 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. |
| CVE-2023-28553 | MEDIUM | 5.5 | 0.1% | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. |
| CVE-2023-46998 | MEDIUM | 6.1 | 1.4% | Nov 7, 2023 | Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary... |
| CVE-2023-35140 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could all... |
| CVE-2023-5976 | MEDIUM | 4.3 | 0.4% | Nov 7, 2023 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-5904 | MEDIUM | 5.4 | 0.4% | Nov 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5903 | MEDIUM | 5.4 | 0.4% | Nov 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5902 | MEDIUM | 4.3 | 0.3% | Nov 7, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5901 | MEDIUM | 4.8 | 0.5% | Nov 7, 2023 | Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5900 | MEDIUM | 4.3 | 0.2% | Nov 7, 2023 | Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5748 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP... |
| CVE-2023-40453 | MEDIUM | 6.5 | 0.9% | Nov 7, 2023 | Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, whi... |
| CVE-2023-38509 | MEDIUM | 4.3 | 0.7% | Nov 7, 2023 | XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-m... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now