2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21247 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a de... |
| CVE-2023-21245 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the loc... |
| CVE-2023-21241 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lea... |
| CVE-2023-21145 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due t... |
| CVE-2023-3635 | HIGH | 7.5 | 1.1% | Jul 12, 2023 | GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to deni... |
| CVE-2023-37965 | HIGH | 7.1 | 0.6% | Jul 12, 2023 | A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permissi... |
| CVE-2023-37964 | HIGH | 8.8 | 0.5% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to ... |
| CVE-2023-37962 | HIGH | 8.8 | 0.4% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attacke... |
| CVE-2023-37961 | HIGH | 8.8 | 0.4% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to t... |
| CVE-2023-37958 | HIGH | 8.8 | 0.5% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attacke... |
| CVE-2023-37957 | HIGH | 8.8 | 0.3% | Jul 12, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attacke... |
| CVE-2023-37949 | HIGH | 7.1 | 0.5% | Jul 12, 2023 | A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read perm... |
| CVE-2023-37946 | HIGH | 8.8 | 0.7% | Jul 12, 2023 | Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login. |
| CVE-2023-29308 | HIGH | 7.8 | 0.3% | Jul 12, 2023 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds write vulnerabi... |
| CVE-2023-29301 | HIGH | 7.5 | 29.1% | Jul 12, 2023 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by ... |
| CVE-2023-29298 | HIGH | 7.5 | 99.8% | Jul 12, 2023 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by ... |
| CVE-2023-3600 | HIGH | 8.8 | 0.5% | Jul 12, 2023 | During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially explo... |
| CVE-2023-20185 | HIGH | 7.4 | 0.3% | Jul 12, 2023 | A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in AC... |
| CVE-2023-3596 | HIGH | 7.5 | 2.1% | Jul 12, 2023 | Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow... |
| CVE-2023-38068 | HIGH | 7.3 | 0.5% | Jul 12, 2023 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms |
| CVE-2023-30429 | HIGH | 8.8 | 0.7% | Jul 12, 2023 | Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: be... |
| CVE-2023-30428 | HIGH | 8.1 | 0.6% | Jul 12, 2023 | Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenti... |
| CVE-2023-3106 | HIGH | 7.8 | 0.3% | Jul 12, 2023 | A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receive... |
| CVE-2023-30929 | HIGH | 7.8 | 0.1% | Jul 12, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit... |
| CVE-2023-30928 | HIGH | 7.8 | 0.1% | Jul 12, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now