2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-29450HIGH7.5JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of u...
CVE-2023-37415HIGH8.8Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on ...
CVE-2023-35069HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Tra...
CVE-2023-37565HIGH8Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute ...
CVE-2023-37564HIGH8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to ex...
CVE-2023-3424HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions sta...
CVE-2023-3343HIGH8.8The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1...
CVE-2023-37562HIGH8.8Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 an...
CVE-2023-34133HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and ...
CVE-2023-38197HIGH7.5An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinit...
CVE-2023-37568HIGH8ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjac...
CVE-2023-37566HIGH8Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attac...
CVE-2023-34129HIGH8.8Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analyt...
CVE-2023-34127HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM...
CVE-2023-34126HIGH8.8Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesyst...
CVE-2023-35694HIGH7.5In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds c...
CVE-2023-35691HIGH7.2there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with S...
CVE-2023-34123HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-S...
CVE-2023-21399HIGH7.8there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local es...
CVE-2023-21257HIGH7.8In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile...
CVE-2023-21256HIGH7.8In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic err...
CVE-2023-21255HIGH7.8In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to loc...
CVE-2023-21254HIGH7.8In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the ...
CVE-2023-21251HIGH7.3In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper in...
CVE-2023-21248HIGH7.8In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now