2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6870MEDIUM4.3Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displaye...
CVE-2023-6869MEDIUM6.5A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow unt...
CVE-2023-6868MEDIUM4.3In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subs...
CVE-2023-6867MEDIUM6.1The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking del...
CVE-2023-6866HIGH8.8TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect Ty...
CVE-2023-6865MEDIUM6.5`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to wr...
CVE-2023-6864HIGH8.8Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence ...
CVE-2023-6863HIGH8.8The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that la...
CVE-2023-6862HIGH8.8A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. Thi...
CVE-2023-6861HIGH8.8The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vu...
CVE-2023-6860MEDIUM6.5The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to esca...
CVE-2023-6859HIGH8.8A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox E...
CVE-2023-6858HIGH8.8Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerabili...
CVE-2023-6857MEDIUM5.3When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary....
CVE-2023-6856HIGH8.8The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM...
CVE-2023-6135MEDIUM4.3Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially all...
CVE-2023-50762MEDIUM4.3When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown ...
CVE-2023-50761MEDIUM4.3The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If...
CVE-2023-6730HIGH8.8Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
CVE-2023-6945MEDIUM4.8A vulnerability has been found in SourceCodester Online Student Management System 1.0 and classified as problematic. Aff...
CVE-2023-49736HIGH8.8A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow fo...
CVE-2023-49734MEDIUM6.5An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be...
CVE-2023-49489MEDIUM6.1Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive in...
CVE-2023-49006MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive...
CVE-2023-46104MEDIUM6.5Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now