2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20936 | HIGH | 7.8 | 0.1% | Mar 24, 2023 | In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2023-20931 | HIGH | 7.8 | 0.1% | Mar 24, 2023 | In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. Thi... |
| CVE-2023-20917 | HIGH | 7.8 | 0.1% | Mar 24, 2023 | In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the ... |
| CVE-2023-20911 | HIGH | 7.8 | 0.2% | Mar 24, 2023 | In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due t... |
| CVE-2023-20906 | HIGH | 7.8 | 0.1% | Mar 24, 2023 | In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after... |
| CVE-2023-28686 | HIGH | 7.1 | 0.7% | Mar 24, 2023 | Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via... |
| CVE-2023-28441 | HIGH | 7.5 | 0.4% | Mar 24, 2023 | smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will hav... |
| CVE-2023-24295 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a ... |
| CVE-2023-28335 | HIGH | 8.8 | 0.4% | Mar 23, 2023 | The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk. |
| CVE-2023-28329 | HIGH | 8.8 | 1.2% | Mar 23, 2023 | Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only avail... |
| CVE-2023-24788 | HIGH | 8.8 | 3.1% | Mar 23, 2023 | NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s... |
| CVE-2023-1252 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations si... |
| CVE-2023-28436 | HIGH | 8 | 0.5% | Mar 23, 2023 | Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the imple... |
| CVE-2023-26360 | HIGH | 8.6 | 97.1% | Mar 23, 2023 | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Acces... |
| CVE-2023-1607 | HIGH | 8.8 | 0.7% | Mar 23, 2023 | A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the f... |
| CVE-2023-1605 | HIGH | 7.5 | 1.0% | Mar 23, 2023 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. |
| CVE-2023-27094 | HIGH | 8.8 | 0.6% | Mar 23, 2023 | An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the ... |
| CVE-2023-20113 | HIGH | 8.1 | 0.3% | Mar 23, 2023 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r... |
| CVE-2023-20107 | HIGH | 7.5 | 0.7% | Mar 23, 2023 | A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in... |
| CVE-2023-20080 | HIGH | 7.5 | 1.0% | Mar 23, 2023 | A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could all... |
| CVE-2023-20072 | HIGH | 8.6 | 1.0% | Mar 23, 2023 | A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an un... |
| CVE-2023-20065 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, lo... |
| CVE-2023-20055 | HIGH | 8.8 | 0.7% | Mar 23, 2023 | A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privi... |
| CVE-2023-20035 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbit... |
| CVE-2023-20029 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now