2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-42539MEDIUM5.5PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows loc...
CVE-2023-42534MEDIUM5.5Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to rea...
CVE-2023-42533MEDIUM6.8Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execut...
CVE-2023-42527MEDIUM5.5Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local a...
CVE-2023-41723MEDIUM4.3A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: ...
CVE-2023-38549MEDIUM5.4A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acqui...
CVE-2023-38548MEDIUM4.3A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acqui...
CVE-2023-47102MEDIUM5.3UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a usernam...
CVE-2023-28569MEDIUM5.5Information disclosure in WLAN HAL while handling command through WMI interfaces.
CVE-2023-28568MEDIUM5.5Information disclosure in WLAN HAL when reception status handler is called.
CVE-2023-28566MEDIUM5.5Information disclosure in WLAN HAL while handling the WMI state info command.
CVE-2023-28563MEDIUM5.5Information disclosure in IOE Firmware while handling WMI command.
CVE-2023-28554MEDIUM5.5Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
CVE-2023-28553MEDIUM5.5Information Disclosure in WLAN Host when processing WMI event command.
CVE-2023-46998MEDIUM6.1Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary...
CVE-2023-35140MEDIUM5.5The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could all...
CVE-2023-5976MEDIUM4.3Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-5904MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5903MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5902MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5901MEDIUM4.8Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5900MEDIUM4.3Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5748MEDIUM5.5Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP...
CVE-2023-40453MEDIUM6.5Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, whi...
CVE-2023-38509MEDIUM4.3XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-m...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now