2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49549 | HIGH | 7.5 | 0.8% | Jan 2, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function i... |
| CVE-2023-48418 | HIGH | 7.8 | 0.2% | Jan 2, 2024 | In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completi... |
| CVE-2023-6339 | CRITICAL | 9.8 | 0.2% | Jan 2, 2024 | Google Nest WiFi Pro root code-execution & user-data compromise |
| CVE-2023-50020 | HIGH | 7.5 | 0.7% | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. |
| CVE-2023-50019 | MEDIUM | 5.9 | 0.6% | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF ... |
| CVE-2023-4164 | MEDIUM | 5.5 | 0.1% | Jan 2, 2024 | There is a possible information disclosure due to a missing permission check. This could lead to local information discl... |
| CVE-2023-47458 | CRITICAL | 9.8 | 0.8% | Jan 2, 2024 | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions c... |
| CVE-2023-45893 | HIGH | 7.5 | 0.6% | Jan 2, 2024 | An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unaut... |
| CVE-2023-45892 | HIGH | 7.5 | 0.6% | Jan 2, 2024 | An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attac... |
| CVE-2023-45561 | MEDIUM | 5.3 | 0.4% | Jan 2, 2024 | An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the ... |
| CVE-2023-6752 | — | — | — | Jan 2, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6747. Reason: This candidate is a r... |
| CVE-2023-51652 | MEDIUM | 6.1 | 0.4% | Jan 2, 2024 | OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0,... |
| CVE-2023-50711 | CRITICAL | 9.8 | 0.7% | Jan 2, 2024 | vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starti... |
| CVE-2023-49794 | HIGH | 7.8 | 0.3% | Jan 2, 2024 | KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in ... |
| CVE-2023-7192 | MEDIUM | 4.4 | 0.3% | Jan 2, 2024 | A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kerne... |
| CVE-2023-48419 | CRITICAL | 9.8 | 0.2% | Jan 2, 2024 | An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege |
| CVE-2023-4280 | CRITICAL | 9.8 | 0.4% | Jan 2, 2024 | An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker ... |
| CVE-2023-48721 | — | — | — | Jan 2, 2024 | Rejected reason: Not used |
| CVE-2023-6436 | CRITICAL | 9.8 | 0.5% | Jan 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics W... |
| CVE-2023-6693 | MEDIUM | 5.3 | 0.3% | Jan 2, 2024 | A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virt... |
| CVE-2023-50333 | MEDIUM | 4.3 | 0.3% | Jan 2, 2024 | Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing fre... |
| CVE-2023-48732 | MEDIUM | 4.3 | 0.5% | Jan 2, 2024 | Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSoc... |
| CVE-2023-47858 | MEDIUM | 4.3 | 0.4% | Jan 2, 2024 | Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of o... |
| CVE-2023-49142 | LOW | 3.3 | 0.2% | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released ... |
| CVE-2023-49135 | MEDIUM | 5.5 | 0.2% | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now