2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47104CRITICAL9.8tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign)...
CVE-2023-43649CRITICAL9.8baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability...
CVE-2023-43648MEDIUM6.5baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the...
CVE-2023-43647MEDIUM5.4baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in th...
CVE-2023-42804MEDIUM5.3BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vuln...
CVE-2023-42803HIGH8.8BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestri...
CVE-2023-41891HIGH8.8FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior...
CVE-2023-47101HIGH7.8The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalati...
CVE-2023-45780HIGH7.3In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to lo...
CVE-2023-40101MEDIUM5.5In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2023-21398HIGH7.8In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to ...
CVE-2023-21397HIGH7.8In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to loc...
CVE-2023-21396HIGH7.8In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to...
CVE-2023-21395MEDIUM6.5In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disc...
CVE-2023-21394MEDIUM5.5In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a ...
CVE-2023-21393HIGH7.8In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to lo...
CVE-2023-21392HIGH8.8In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of ...
CVE-2023-21391HIGH7.5In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could ...
CVE-2023-21390HIGH7.8In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to l...
CVE-2023-21389HIGH7.8In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead...
CVE-2023-21388HIGH7.8In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalati...
CVE-2023-21387MEDIUM4.4In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log inform...
CVE-2023-21385MEDIUM5.5In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information di...
CVE-2023-21384MEDIUM5.5In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to l...
CVE-2023-21383MEDIUM5.5In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This coul...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now