2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38852 | MEDIUM | 6.5 | 1.2% | Aug 15, 2023 | Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ... |
| CVE-2023-38851 | MEDIUM | 6.5 | 0.8% | Aug 15, 2023 | Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ... |
| CVE-2023-38850 | MEDIUM | 5.5 | 0.2% | Aug 15, 2023 | Buffer Overflow vulnerability in Michaelrsweet codedoc v.3.7 allows an attacker to cause a denial of service via the cod... |
| CVE-2023-38840 | MEDIUM | 5.5 | 0.6% | Aug 15, 2023 | Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwar... |
| CVE-2023-32003 | MEDIUM | 5.3 | 1.0% | Aug 15, 2023 | `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. Th... |
| CVE-2023-4371 | MEDIUM | 6.1 | 0.3% | Aug 15, 2023 | A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown fu... |
| CVE-2023-30778 | MEDIUM | 5.4 | 0.3% | Aug 15, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry ... |
| CVE-2023-30747 | MEDIUM | 6.1 | 0.4% | Aug 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGem WooCommerce Easy Duplicate Product plugin <= 0.3.0.0... |
| CVE-2023-30498 | MEDIUM | 6.1 | 0.4% | Aug 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 v... |
| CVE-2023-24478 | MEDIUM | 5.5 | 0.2% | Aug 15, 2023 | Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro ... |
| CVE-2023-2916 | MEDIUM | 5.3 | 20.9% | Aug 15, 2023 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ... |
| CVE-2023-4308 | MEDIUM | 5.4 | 0.4% | Aug 15, 2023 | The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-conte... |
| CVE-2023-4347 | MEDIUM | 5.4 | 66.9% | Aug 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. |
| CVE-2023-28199 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input ... |
| CVE-2023-27948 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin... |
| CVE-2023-27947 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin... |
| CVE-2023-27939 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin... |
| CVE-2023-21292 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted fil... |
| CVE-2023-21290 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This co... |
| CVE-2023-21289 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could... |
| CVE-2023-21288 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission che... |
| CVE-2023-21285 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deput... |
| CVE-2023-21284 | MEDIUM | 5.5 | 0.2% | Aug 14, 2023 | In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device featur... |
| CVE-2023-21283 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deput... |
| CVE-2023-21280 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaust... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now