2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40109HIGH7.8In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions ...
CVE-2023-40107HIGH7.8In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local ...
CVE-2023-40106HIGH7.8In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due...
CVE-2023-40105MEDIUM5.5In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing pe...
CVE-2023-40104HIGH7.5In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This...
CVE-2023-40100HIGH7.8In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could...
CVE-2023-6123MEDIUM6.1Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could re...
CVE-2023-40057CRITICAL9The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited,...
CVE-2023-6937MEDIUM5.3wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was ...
CVE-2023-7081CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online P...
CVE-2023-6255HIGH7.5Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive ...
CVE-2023-5155CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information...
CVE-2023-4993HIGH7.5Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data...
CVE-2023-47537MEDIUM4.8An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, F...
CVE-2023-45581HIGH7.2An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and befo...
CVE-2023-44253MEDIUM5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7...
CVE-2023-26206MEDIUM6.1An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4...
CVE-2023-39245CRITICAL9.8 DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability i...
CVE-2023-39244CRITICAL9.8DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in...
CVE-2023-32484CRITICAL9.8 Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input val...
CVE-2023-32462CRITICAL9.8 Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remot...
CVE-2023-28078CRITICAL9.1 Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A ...
CVE-2023-4539HIGH7.5Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacke...
CVE-2023-4538MEDIUM6.5The database access credentials configured during installation are stored in a special table, and are encrypted with a s...
CVE-2023-4537HIGH7.4Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unenc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now