2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-30672MEDIUM5.5Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 a...
CVE-2023-30671MEDIUM5.5Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade ...
CVE-2023-30665MEDIUM4.4Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local a...
CVE-2023-30662MEDIUM5.5Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 a...
CVE-2023-30661MEDIUM5.5Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1...
CVE-2023-30660MEDIUM5.5Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Relea...
CVE-2023-30648MEDIUM5.5Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denia...
CVE-2023-30642MEDIUM5.5Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attack...
CVE-2023-30641MEDIUM4.3Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restri...
CVE-2023-3521MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
CVE-2023-29656MEDIUM6.1An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and lo...
CVE-2023-27225MEDIUM5.4A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 a...
CVE-2023-3520MEDIUM4.6Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
CVE-2023-36828MEDIUM5.4Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does n...
CVE-2023-36809MEDIUM5.4Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Vers...
CVE-2023-35936MEDIUM5Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this lib...
CVE-2023-30207MEDIUM5.5A divide by zero issue discovered in Kodi Home Theater Software 19.5 and earlier allows attackers to cause a denial of s...
CVE-2023-34654MEDIUM6.1taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34244MEDIUM6.1GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malici...
CVE-2023-34107MEDIUM6.5GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0....
CVE-2023-27199MEDIUM6.7PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and us...
CVE-2023-27198MEDIUM6.8PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the e...
CVE-2023-27197MEDIUM6.7PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a craft...
CVE-2023-34472MEDIUM6.5AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in ...
CVE-2023-35863MEDIUM5.3In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now