2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21440 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a... |
| CVE-2023-21437 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to acc... |
| CVE-2023-21435 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to ac... |
| CVE-2023-21434 | MEDIUM | 6.1 | 12.9% | Feb 9, 2023 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute Java... |
| CVE-2023-21427 | MEDIUM | 6.5 | 0.3% | Feb 9, 2023 | Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without u... |
| CVE-2023-21426 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardem... |
| CVE-2023-21425 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to g... |
| CVE-2023-21423 | MEDIUM | 5.5 | 0.1% | Feb 9, 2023 | Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE a... |
| CVE-2023-21422 | MEDIUM | 5.5 | 0.1% | Feb 9, 2023 | Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attacke... |
| CVE-2023-24815 | MEDIUM | 5.3 | 0.9% | Feb 9, 2023 | Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vert... |
| CVE-2023-0624 | MEDIUM | 6.1 | 0.5% | Feb 9, 2023 | OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is p... |
| CVE-2023-25163 | MEDIUM | 6.5 | 0.8% | Feb 8, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-r... |
| CVE-2023-25167 | MEDIUM | 5.7 | 0.6% | Feb 8, 2023 | Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de... |
| CVE-2023-25166 | MEDIUM | 6.5 | 0.6% | Feb 8, 2023 | formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parse... |
| CVE-2023-25165 | MEDIUM | 4.3 | 0.8% | Feb 8, 2023 | Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template funct... |
| CVE-2023-25150 | MEDIUM | 5.7 | 0.7% | Feb 8, 2023 | Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i... |
| CVE-2023-0751 | MEDIUM | 6.5 | 0.6% | Feb 8, 2023 | When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once ... |
| CVE-2023-23475 | MEDIUM | 4.6 | 0.3% | Feb 8, 2023 | IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-0003 | MEDIUM | 6.5 | 1.2% | Feb 8, 2023 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit... |
| CVE-2023-0001 | MEDIUM | 6.7 | 0.2% | Feb 8, 2023 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste... |
| CVE-2023-0748 | MEDIUM | 6.1 | 0.6% | Feb 8, 2023 | Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. |
| CVE-2023-0747 | MEDIUM | 5.4 | 0.5% | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. |
| CVE-2023-0739 | MEDIUM | 6.8 | 0.7% | Feb 8, 2023 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerd... |
| CVE-2023-0726 | MEDIUM | 4.3 | 0.3% | Feb 8, 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.... |
| CVE-2023-0725 | MEDIUM | 4.3 | 0.3% | Feb 8, 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now