2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0383 | HIGH | 7.5 | 0.9% | Apr 20, 2023 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol... |
| CVE-2023-28047 | HIGH | 7.8 | 0.2% | Apr 20, 2023 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during inst... |
| CVE-2023-30797 | HIGH | 7.5 | 0.8% | Apr 19, 2023 | Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficie... |
| CVE-2023-28122 | HIGH | 7.8 | 0.2% | Apr 19, 2023 | A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a mali... |
| CVE-2023-21100 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local... |
| CVE-2023-21099 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the backg... |
| CVE-2023-21098 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Setti... |
| CVE-2023-21097 | HIGH | 7.8 | 0.2% | Apr 19, 2023 | In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This cou... |
| CVE-2023-21094 | HIGH | 7.8 | 0.2% | Apr 19, 2023 | In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due ... |
| CVE-2023-21093 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other appl... |
| CVE-2023-21092 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver usi... |
| CVE-2023-21089 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive whi... |
| CVE-2023-21088 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch ... |
| CVE-2023-21086 | HIGH | 7.8 | 0.2% | Apr 19, 2023 | In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC f... |
| CVE-2023-21085 | HIGH | 8.8 | 0.2% | Apr 19, 2023 | In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2023-21083 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without showing a privacy i... |
| CVE-2023-21081 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background ac... |
| CVE-2023-20967 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check... |
| CVE-2023-20950 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restr... |
| CVE-2023-22893 | HIGH | 7.5 | 4.2% | Apr 19, 2023 | Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro... |
| CVE-2023-22621 | HIGH | 7.2 | 76.8% | Apr 19, 2023 | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra... |
| CVE-2023-30463 | HIGH | 7.5 | 0.9% | Apr 19, 2023 | Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow ... |
| CVE-2023-25760 | HIGH | 8.8 | 0.6% | Apr 19, 2023 | Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify othe... |
| CVE-2023-22645 | HIGH | 8.8 | 0.5% | Apr 19, 2023 | An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get... |
| CVE-2023-25619 | HIGH | 7.5 | 0.6% | Apr 19, 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now