2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40416MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 1...
CVE-2023-40413MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Montere...
CVE-2023-40408MEDIUM5.3An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 1...
CVE-2023-40405LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma ...
CVE-2023-40404HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app m...
CVE-2023-40401HIGH7.5The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may...
CVE-2023-32359HIGH7.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS ...
CVE-2023-5758MEDIUM6.1When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflec...
CVE-2023-5753HIGH8.8Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c
CVE-2023-5752LOW3.3When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Me...
CVE-2023-5746CRITICAL9.8A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote a...
CVE-2023-5745MEDIUM5.4The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode i...
CVE-2023-5744MEDIUM5.4The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vsgmap' ...
CVE-2023-5740MEDIUM5.4The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2023-5732MEDIUM6.5An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar ...
CVE-2023-5731CRITICAL9.8Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-5730CRITICAL9.8Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence ...
CVE-2023-5729MEDIUM4.3A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscur...
CVE-2023-5728HIGH7.5During garbage collection extra operations were performed on a object that should not be. This could have led to a poten...
CVE-2023-5727MEDIUM6.5The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which c...
CVE-2023-5726MEDIUM4.3A website could have obscured the full screen notification by using the file open dialog. This could have led to user co...
CVE-2023-5725MEDIUM4.3A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to c...
CVE-2023-5724HIGH7.5Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. T...
CVE-2023-5723MEDIUM5.3An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document...
CVE-2023-5722MEDIUM5.3Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a serv...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now