2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22796 | HIGH | 7.5 | 1.7% | Feb 9, 2023 | A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed ... |
| CVE-2023-22795 | HIGH | 7.5 | 2.3% | Feb 9, 2023 | A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match heade... |
| CVE-2023-22794 | HIGH | 8.8 | 2.2% | Feb 9, 2023 | A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious us... |
| CVE-2023-22792 | HIGH | 7.5 | 1.7% | Feb 9, 2023 | A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cook... |
| CVE-2023-21451 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause ... |
| CVE-2023-21445 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12... |
| CVE-2023-21444 | HIGH | 8.8 | 0.2% | Feb 9, 2023 | Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted mes... |
| CVE-2023-21443 | HIGH | 8.8 | 0.2% | Feb 9, 2023 | Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to d... |
| CVE-2023-21439 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to laun... |
| CVE-2023-21433 | HIGH | 7.8 | 3.7% | Feb 9, 2023 | Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applic... |
| CVE-2023-21432 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without auth... |
| CVE-2023-21430 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to ... |
| CVE-2023-21421 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2... |
| CVE-2023-21420 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary c... |
| CVE-2023-21419 | HIGH | 7.5 | 0.2% | Feb 9, 2023 | An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container rem... |
| CVE-2023-22953 | HIGH | 8.8 | 1.4% | Feb 9, 2023 | In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. |
| CVE-2023-0760 | HIGH | 7.8 | 0.4% | Feb 9, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. |
| CVE-2023-0759 | HIGH | 8.8 | 0.3% | Feb 9, 2023 | Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. |
| CVE-2023-25168 | HIGH | 8.2 | 1.0% | Feb 9, 2023 | Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively ... |
| CVE-2023-0251 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restriction... |
| CVE-2023-0250 | HIGH | 7.8 | 2.2% | Feb 8, 2023 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could all... |
| CVE-2023-0249 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attack... |
| CVE-2023-25164 | HIGH | 7.5 | 0.7% | Feb 8, 2023 | Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina... |
| CVE-2023-25151 | HIGH | 7.5 | 1.0% | Feb 8, 2023 | opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io... |
| CVE-2023-0401 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In cas... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now