2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39438 | HIGH | 8.1 | 0.4% | Aug 15, 2023 | A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CL... |
| CVE-2023-38916 | HIGH | 8.8 | 0.9% | Aug 15, 2023 | SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sen... |
| CVE-2023-32006 | HIGH | 8.8 | 1.3% | Aug 15, 2023 | The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the polic... |
| CVE-2023-32004 | HIGH | 8.8 | 1.8% | Aug 15, 2023 | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f... |
| CVE-2023-28479 | HIGH | 8.8 | 0.7% | Aug 15, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain wi... |
| CVE-2023-32358 | HIGH | 8.8 | 0.6% | Aug 14, 2023 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventur... |
| CVE-2023-28198 | HIGH | 8.8 | 0.8% | Aug 14, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, m... |
| CVE-2023-28179 | HIGH | 7.1 | 0.2% | Aug 14, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a malicious... |
| CVE-2023-40518 | HIGH | 7.5 | 0.5% | Aug 14, 2023 | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers. |
| CVE-2023-35689 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion d... |
| CVE-2023-21286 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec... |
| CVE-2023-21282 | HIGH | 8.8 | 1.0% | Aug 14, 2023 | In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This cou... |
| CVE-2023-21281 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a lo... |
| CVE-2023-21275 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory ... |
| CVE-2023-21273 | HIGH | 8.8 | 0.2% | Aug 14, 2023 | In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could l... |
| CVE-2023-21272 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead ... |
| CVE-2023-21235 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing... |
| CVE-2023-21233 | HIGH | 7.5 | 0.3% | Aug 14, 2023 | In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remot... |
| CVE-2023-21231 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-expo... |
| CVE-2023-21229 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions ... |
| CVE-2023-40020 | HIGH | 8.3 | 0.4% | Aug 14, 2023 | PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v... |
| CVE-2023-39829 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWire... |
| CVE-2023-39828 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet fun... |
| CVE-2023-39827 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRul... |
| CVE-2023-21269 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now