2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-23609HIGH7.4Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and inc...
CVE-2023-22736HIGH8.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, pr...
CVE-2023-22500HIGH7.5GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to In...
CVE-2023-22486HIGH7.5cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29...
CVE-2023-22482HIGH8.8Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and p...
CVE-2023-20928HIGH7.8In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local es...
CVE-2023-20925HIGH7.8In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. Thi...
CVE-2023-20921HIGH7.3In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility ser...
CVE-2023-20920HIGH7.8In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local...
CVE-2023-20919HIGH7.8In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error i...
CVE-2023-20916HIGH7.8In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti...
CVE-2023-20915HIGH7.8In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without use...
CVE-2023-20913HIGH7.8In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into ena...
CVE-2023-20912HIGH7.8In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due ...
CVE-2023-20905HIGH7.8In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2023-20904HIGH7.8In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent misma...
CVE-2023-0516HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit...
CVE-2023-0515HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Thi...
CVE-2023-0451HIGH7.5Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certai...
CVE-2023-0444HIGH8.8A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'Use...
CVE-2023-0412HIGH7.1TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection o...
CVE-2023-0356HIGH7.5 SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which ...
CVE-2023-0284HIGH8.1Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipul...
CVE-2023-21796HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-21795HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now