2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25601 | MEDIUM | 4.3 | 1.1% | Apr 20, 2023 | On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attac... |
| CVE-2023-27652 | MEDIUM | 5.5 | 0.3% | Apr 20, 2023 | An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of serv... |
| CVE-2023-22309 | MEDIUM | 6.1 | 0.4% | Apr 20, 2023 | Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4. |
| CVE-2023-1767 | MEDIUM | 5.4 | 0.5% | Apr 20, 2023 | The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature o... |
| CVE-2023-2191 | MEDIUM | 4.8 | 0.5% | Apr 20, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18. |
| CVE-2023-2166 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may no... |
| CVE-2023-28328 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel... |
| CVE-2023-28327 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Ke... |
| CVE-2023-1382 | MEDIUM | 4.7 | 0.2% | Apr 19, 2023 | A data race flaw was found in the Linux kernel, between where con is allocated and con->sock is set. This issue leads to... |
| CVE-2023-2162 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-componen... |
| CVE-2023-28124 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with ... |
| CVE-2023-28123 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VP... |
| CVE-2023-21091 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a miss... |
| CVE-2023-21090 | MEDIUM | 5 | 0.1% | Apr 19, 2023 | In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could... |
| CVE-2023-21087 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to lo... |
| CVE-2023-21084 | MEDIUM | 6.7 | 0.1% | Apr 19, 2023 | In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypto. This could lead t... |
| CVE-2023-21082 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's c... |
| CVE-2023-21080 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This c... |
| CVE-2023-20941 | MEDIUM | 6.6 | 0.2% | Apr 19, 2023 | In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. Th... |
| CVE-2023-20935 | MEDIUM | 5.5 | 0.1% | Apr 19, 2023 | In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2023-20909 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. T... |
| CVE-2023-20862 | MEDIUM | 6.3 | 0.6% | Apr 19, 2023 | In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the... |
| CVE-2023-29922 | MEDIUM | 5.3 | 3.0% | Apr 19, 2023 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. |
| CVE-2023-1900 | MEDIUM | 5.5 | 0.3% | Apr 19, 2023 | A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an ... |
| CVE-2023-1587 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue wa... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now