2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40117HIGH7.8In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This...
CVE-2023-40116HIGH7.8In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions du...
CVE-2023-35794HIGH8.8An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) ca...
CVE-2023-32738MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 vers...
CVE-2023-5829HIGH8.8A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by t...
CVE-2023-5828CRITICAL9.8A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation M...
CVE-2023-46853CRITICAL9.8In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used inste...
CVE-2023-46852HIGH7.5In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many ...
CVE-2023-46407MEDIUM5.5FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the...
CVE-2023-29009MEDIUM6.1baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in ...
CVE-2023-4967HIGH7.5Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CV...
CVE-2023-46290HIGH8.1 Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS use...
CVE-2023-46289HIGH7.5 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow th...
CVE-2023-46246MEDIUM5.5Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_g...
CVE-2023-27858HIGH7.8 Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a ...
CVE-2023-27854HIGH7.8 An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentiall...
CVE-2023-5827CRITICAL9.8A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified...
CVE-2023-5826HIGH8.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t...
CVE-2023-46604CRITICAL9.8The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote att...
CVE-2023-5443HIGH7.5Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Acco...
CVE-2023-46394MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to exe...
CVE-2023-46393HIGH7.5gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrari...
CVE-2023-5807CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Edu...
CVE-2023-44377Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44376Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now