2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-20936HIGH7.8In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2023-20931HIGH7.8In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. Thi...
CVE-2023-20917HIGH7.8In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the ...
CVE-2023-20911HIGH7.8In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due t...
CVE-2023-20906HIGH7.8In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after...
CVE-2023-28686HIGH7.1Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via...
CVE-2023-28441HIGH7.5smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will hav...
CVE-2023-24295HIGH7.8A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a ...
CVE-2023-28335HIGH8.8The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
CVE-2023-28329HIGH8.8Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only avail...
CVE-2023-24788HIGH8.8NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s...
CVE-2023-1252HIGH7.8A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations si...
CVE-2023-28436HIGH8Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the imple...
CVE-2023-26360HIGH8.6Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Acces...
CVE-2023-1607HIGH8.8A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the f...
CVE-2023-1605HIGH7.5Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
CVE-2023-27094HIGH8.8An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the ...
CVE-2023-20113HIGH8.1A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r...
CVE-2023-20107HIGH7.5A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in...
CVE-2023-20080HIGH7.5A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could all...
CVE-2023-20072HIGH8.6A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an un...
CVE-2023-20065HIGH7.8A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, lo...
CVE-2023-20055HIGH8.8A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privi...
CVE-2023-20035HIGH7.8A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbit...
CVE-2023-20029HIGH7.8A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now