2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-21440MEDIUM5.5Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a...
CVE-2023-21437MEDIUM5.5Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to acc...
CVE-2023-21435MEDIUM5.5Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to ac...
CVE-2023-21434MEDIUM6.1Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute Java...
CVE-2023-21427MEDIUM6.5Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without u...
CVE-2023-21426MEDIUM5.5Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardem...
CVE-2023-21425MEDIUM5.5Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to g...
CVE-2023-21423MEDIUM5.5Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE a...
CVE-2023-21422MEDIUM5.5Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attacke...
CVE-2023-24815MEDIUM5.3Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vert...
CVE-2023-0624MEDIUM6.1OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is p...
CVE-2023-25163MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-r...
CVE-2023-25167MEDIUM5.7Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de...
CVE-2023-25166MEDIUM6.5formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parse...
CVE-2023-25165MEDIUM4.3Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template funct...
CVE-2023-25150MEDIUM5.7Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i...
CVE-2023-0751MEDIUM6.5When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once ...
CVE-2023-23475MEDIUM4.6IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-0003MEDIUM6.5A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit...
CVE-2023-0001MEDIUM6.7An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste...
CVE-2023-0748MEDIUM6.1Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVE-2023-0747MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVE-2023-0739MEDIUM6.8Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerd...
CVE-2023-0726MEDIUM4.3The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2....
CVE-2023-0725MEDIUM4.3The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now