2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40117 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This... |
| CVE-2023-40116 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions du... |
| CVE-2023-35794 | HIGH | 8.8 | 0.9% | Oct 27, 2023 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) ca... |
| CVE-2023-32738 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 vers... |
| CVE-2023-5829 | HIGH | 8.8 | 0.8% | Oct 27, 2023 | A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2023-5828 | CRITICAL | 9.8 | 0.7% | Oct 27, 2023 | A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation M... |
| CVE-2023-46853 | CRITICAL | 9.8 | 0.8% | Oct 27, 2023 | In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used inste... |
| CVE-2023-46852 | HIGH | 7.5 | 0.8% | Oct 27, 2023 | In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many ... |
| CVE-2023-46407 | MEDIUM | 5.5 | 0.3% | Oct 27, 2023 | FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the... |
| CVE-2023-29009 | MEDIUM | 6.1 | 0.5% | Oct 27, 2023 | baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in ... |
| CVE-2023-4967 | HIGH | 7.5 | 0.9% | Oct 27, 2023 | Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CV... |
| CVE-2023-46290 | HIGH | 8.1 | 2.7% | Oct 27, 2023 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS use... |
| CVE-2023-46289 | HIGH | 7.5 | 0.9% | Oct 27, 2023 | Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow th... |
| CVE-2023-46246 | MEDIUM | 5.5 | 0.4% | Oct 27, 2023 | Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_g... |
| CVE-2023-27858 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a ... |
| CVE-2023-27854 | HIGH | 7.8 | 0.3% | Oct 27, 2023 | An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentiall... |
| CVE-2023-5827 | CRITICAL | 9.8 | 0.7% | Oct 27, 2023 | A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified... |
| CVE-2023-5826 | HIGH | 8.8 | 0.7% | Oct 27, 2023 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t... |
| CVE-2023-46604 | CRITICAL | 9.8 | 99.7% | Oct 27, 2023 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote att... |
| CVE-2023-5443 | HIGH | 7.5 | 0.4% | Oct 27, 2023 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Acco... |
| CVE-2023-46394 | MEDIUM | 5.4 | 0.3% | Oct 27, 2023 | A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to exe... |
| CVE-2023-46393 | HIGH | 7.5 | 0.4% | Oct 27, 2023 | gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrari... |
| CVE-2023-5807 | CRITICAL | 9.8 | 0.5% | Oct 27, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Edu... |
| CVE-2023-44377 | — | — | — | Oct 27, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44376 | — | — | — | Oct 27, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now