2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21279 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to... |
| CVE-2023-21277 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec... |
| CVE-2023-21276 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could l... |
| CVE-2023-21274 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2023-21271 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This c... |
| CVE-2023-21234 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options with... |
| CVE-2023-21230 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadc... |
| CVE-2023-40013 | MEDIUM | 5.4 | 0.5% | Aug 14, 2023 | SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. ... |
| CVE-2023-39950 | MEDIUM | 5.2 | 0.4% | Aug 14, 2023 | efibootguard is a simple UEFI boot loader with support for safely switching between current and updated partition sets. ... |
| CVE-2023-38687 | MEDIUM | 5.4 | 0.5% | Aug 14, 2023 | Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML wit... |
| CVE-2023-21268 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. Th... |
| CVE-2023-21267 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning ... |
| CVE-2023-21264 | MEDIUM | 6.7 | 0.2% | Aug 14, 2023 | In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check... |
| CVE-2023-21140 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21134 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21133 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21132 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-40024 | MEDIUM | 6.1 | 0.4% | Aug 14, 2023 | ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the... |
| CVE-2023-3721 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-3645 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, wh... |
| CVE-2023-3601 | MEDIUM | 4.3 | 0.4% | Aug 14, 2023 | The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that us... |
| CVE-2023-3328 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which... |
| CVE-2023-2803 | MEDIUM | 6.1 | 0.5% | Aug 14, 2023 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before ou... |
| CVE-2023-2802 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings,... |
| CVE-2023-2606 | MEDIUM | 4.8 | 2.0% | Aug 14, 2023 | The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now