2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38852MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38851MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38850MEDIUM5.5Buffer Overflow vulnerability in Michaelrsweet codedoc v.3.7 allows an attacker to cause a denial of service via the cod...
CVE-2023-38840MEDIUM5.5Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwar...
CVE-2023-32003MEDIUM5.3`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. Th...
CVE-2023-4371MEDIUM6.1A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown fu...
CVE-2023-30778MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry ...
CVE-2023-30747MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGem WooCommerce Easy Duplicate Product plugin <= 0.3.0.0...
CVE-2023-30498MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 v...
CVE-2023-24478MEDIUM5.5Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro ...
CVE-2023-2916MEDIUM5.3The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ...
CVE-2023-4308MEDIUM5.4The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-conte...
CVE-2023-4347MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
CVE-2023-28199MEDIUM5.5An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input ...
CVE-2023-27948MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-27947MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-27939MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-21292MEDIUM5.5In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted fil...
CVE-2023-21290MEDIUM5.5In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This co...
CVE-2023-21289MEDIUM5.5In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could...
CVE-2023-21288MEDIUM5.5In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission che...
CVE-2023-21285MEDIUM5.5In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deput...
CVE-2023-21284MEDIUM5.5In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device featur...
CVE-2023-21283MEDIUM5.5In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deput...
CVE-2023-21280MEDIUM5.5In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaust...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now