2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-22796HIGH7.5A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed ...
CVE-2023-22795HIGH7.5A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match heade...
CVE-2023-22794HIGH8.8A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious us...
CVE-2023-22792HIGH7.5A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cook...
CVE-2023-21451HIGH7.8A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause ...
CVE-2023-21445HIGH7.8Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12...
CVE-2023-21444HIGH8.8Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted mes...
CVE-2023-21443HIGH8.8Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to d...
CVE-2023-21439HIGH7.8Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to laun...
CVE-2023-21433HIGH7.8Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applic...
CVE-2023-21432HIGH7.8Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without auth...
CVE-2023-21430HIGH7.8An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to ...
CVE-2023-21421HIGH7.8Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2...
CVE-2023-21420HIGH7.8Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary c...
CVE-2023-21419HIGH7.5An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container rem...
CVE-2023-22953HIGH8.8In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
CVE-2023-0760HIGH7.8Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
CVE-2023-0759HIGH8.8Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
CVE-2023-25168HIGH8.2Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively ...
CVE-2023-0251HIGH7.8Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restriction...
CVE-2023-0250HIGH7.8Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could all...
CVE-2023-0249HIGH7.8Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attack...
CVE-2023-25164HIGH7.5Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina...
CVE-2023-25151HIGH7.5opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io...
CVE-2023-0401HIGH7.5A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In cas...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now