2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-35674HIGH7.8In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod...
CVE-2023-35673HIGH8.8In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could le...
CVE-2023-35670HIGH7.8In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private dire...
CVE-2023-35669HIGH7.8In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activ...
CVE-2023-35667HIGH7.8In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the...
CVE-2023-35666HIGH7.8In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead ...
CVE-2023-35665HIGH7.8In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This...
CVE-2023-35658HIGH8.8In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This cou...
CVE-2023-4314HIGH7.2The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deseriali...
CVE-2023-4278HIGH7.5The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registra...
CVE-2023-39227HIGH7.5​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers ...
CVE-2023-38256HIGH7.5Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3....
CVE-2023-36497HIGH8.8Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3....
CVE-2023-39780HIGH8.8On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply...
CVE-2023-39070HIGH7.8An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in...
CVE-2023-39068HIGH7.5Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N...
CVE-2023-39063HIGH7.8Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server na...
CVE-2023-38829HIGH8.8An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and tracer...
CVE-2023-38743HIGH7.2Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
CVE-2023-31468HIGH7.8An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I...
CVE-2023-27470HIGH7BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a ps...
CVE-2023-36161HIGH7.5An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of ...
CVE-2023-3612HIGH8.8Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an U...
CVE-2023-4585HIGH8.8Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence ...
CVE-2023-4584HIGH8.8Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 11...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now