2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-0383HIGH7.5User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol...
CVE-2023-28047HIGH7.8 Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during inst...
CVE-2023-30797HIGH7.5Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficie...
CVE-2023-28122HIGH7.8A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a mali...
CVE-2023-21100HIGH7.8In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local...
CVE-2023-21099HIGH7.8In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the backg...
CVE-2023-21098HIGH7.8In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Setti...
CVE-2023-21097HIGH7.8In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This cou...
CVE-2023-21094HIGH7.8In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due ...
CVE-2023-21093HIGH7.8In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other appl...
CVE-2023-21092HIGH7.8In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver usi...
CVE-2023-21089HIGH7.8In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive whi...
CVE-2023-21088HIGH7.8In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch ...
CVE-2023-21086HIGH7.8In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC f...
CVE-2023-21085HIGH8.8In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2023-21083HIGH7.8In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without showing a privacy i...
CVE-2023-21081HIGH7.8In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background ac...
CVE-2023-20967HIGH7.8In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check...
CVE-2023-20950HIGH7.8In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restr...
CVE-2023-22893HIGH7.5Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro...
CVE-2023-22621HIGH7.2Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra...
CVE-2023-30463HIGH7.5Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow ...
CVE-2023-25760HIGH8.8Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify othe...
CVE-2023-22645HIGH8.8An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get...
CVE-2023-25619HIGH7.5 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now