2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-21279MEDIUM5.5In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to...
CVE-2023-21277MEDIUM5.5In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec...
CVE-2023-21276MEDIUM5.5In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could l...
CVE-2023-21274MEDIUM5.5In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2023-21271MEDIUM5.5In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This c...
CVE-2023-21234MEDIUM5.5In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options with...
CVE-2023-21230MEDIUM5.5In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadc...
CVE-2023-40013MEDIUM5.4SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. ...
CVE-2023-39950MEDIUM5.2efibootguard is a simple UEFI boot loader with support for safely switching between current and updated partition sets. ...
CVE-2023-38687MEDIUM5.4Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML wit...
CVE-2023-21268MEDIUM5.5In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. Th...
CVE-2023-21267MEDIUM5.5In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning ...
CVE-2023-21264MEDIUM6.7In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check...
CVE-2023-21140MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21134MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21133MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21132MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-40024MEDIUM6.1ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the...
CVE-2023-3721MEDIUM4.8The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-3645MEDIUM4.8The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, wh...
CVE-2023-3601MEDIUM4.3The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that us...
CVE-2023-3328MEDIUM4.8The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which...
CVE-2023-2803MEDIUM6.1The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before ou...
CVE-2023-2802MEDIUM4.8The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings,...
CVE-2023-2606MEDIUM4.8The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now