2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49549HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function i...
CVE-2023-48418HIGH7.8In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completi...
CVE-2023-6339CRITICAL9.8Google Nest WiFi Pro root code-execution & user-data compromise
CVE-2023-50020HIGH7.5An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
CVE-2023-50019MEDIUM5.9An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF ...
CVE-2023-4164MEDIUM5.5There is a possible information disclosure due to a missing permission check. This could lead to local information discl...
CVE-2023-47458CRITICAL9.8An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions c...
CVE-2023-45893HIGH7.5An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unaut...
CVE-2023-45892HIGH7.5An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attac...
CVE-2023-45561MEDIUM5.3An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the ...
CVE-2023-6752Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6747. Reason: This candidate is a r...
CVE-2023-51652MEDIUM6.1OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0,...
CVE-2023-50711CRITICAL9.8vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starti...
CVE-2023-49794HIGH7.8KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in ...
CVE-2023-7192MEDIUM4.4A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kerne...
CVE-2023-48419CRITICAL9.8An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
CVE-2023-4280CRITICAL9.8An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker ...
CVE-2023-48721Rejected reason: Not used
CVE-2023-6436CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics W...
CVE-2023-6693MEDIUM5.3A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virt...
CVE-2023-50333MEDIUM4.3Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing fre...
CVE-2023-48732MEDIUM4.3Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSoc...
CVE-2023-47858MEDIUM4.3Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of o...
CVE-2023-49142LOW3.3 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released ...
CVE-2023-49135MEDIUM5.5 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now