2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-39438HIGH8.1A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CL...
CVE-2023-38916HIGH8.8SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sen...
CVE-2023-32006HIGH8.8The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the polic...
CVE-2023-32004HIGH8.8A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f...
CVE-2023-28479HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain wi...
CVE-2023-32358HIGH8.8A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventur...
CVE-2023-28198HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, m...
CVE-2023-28179HIGH7.1The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a malicious...
CVE-2023-40518HIGH7.5LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
CVE-2023-35689HIGH7.8In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion d...
CVE-2023-21286HIGH7.8In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec...
CVE-2023-21282HIGH8.8In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This cou...
CVE-2023-21281HIGH7.8In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a lo...
CVE-2023-21275HIGH7.8In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory ...
CVE-2023-21273HIGH8.8In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could l...
CVE-2023-21272HIGH7.8In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead ...
CVE-2023-21235HIGH7.8In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing...
CVE-2023-21233HIGH7.5In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remot...
CVE-2023-21231HIGH7.8In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-expo...
CVE-2023-21229HIGH7.8In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions ...
CVE-2023-40020HIGH8.3PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v...
CVE-2023-39829HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWire...
CVE-2023-39828HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet fun...
CVE-2023-39827HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRul...
CVE-2023-21269HIGH7.8In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now