2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-21247HIGH7.8In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a de...
CVE-2023-21245HIGH7.8In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the loc...
CVE-2023-21241HIGH7.8In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lea...
CVE-2023-21145HIGH7.8In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due t...
CVE-2023-3635HIGH7.5GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to deni...
CVE-2023-37965HIGH7.1A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permissi...
CVE-2023-37964HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to ...
CVE-2023-37962HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attacke...
CVE-2023-37961HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to t...
CVE-2023-37958HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attacke...
CVE-2023-37957HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attacke...
CVE-2023-37949HIGH7.1A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read perm...
CVE-2023-37946HIGH8.8Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
CVE-2023-29308HIGH7.8Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds write vulnerabi...
CVE-2023-29301HIGH7.5Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by ...
CVE-2023-29298HIGH7.5Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by ...
CVE-2023-3600HIGH8.8During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially explo...
CVE-2023-20185HIGH7.4A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in AC...
CVE-2023-3596HIGH7.5 Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow...
CVE-2023-38068HIGH7.3In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
CVE-2023-30429HIGH8.8Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: be...
CVE-2023-30428HIGH8.1Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenti...
CVE-2023-3106HIGH7.8A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receive...
CVE-2023-30929HIGH7.8In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit...
CVE-2023-30928HIGH7.8In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now