2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40634HIGH7.8In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with...
CVE-2023-40633MEDIUM5.5In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with ...
CVE-2023-40632HIGH7.5In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure...
CVE-2023-40631MEDIUM4.4In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System exe...
CVE-2023-45199CRITICAL9.8Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-43615HIGH7.5Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
CVE-2023-5182MEDIUM5.5Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use...
CVE-2023-36123HIGH7.8Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to ex...
CVE-2023-44860HIGH7.5An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization ...
CVE-2023-44061HIGH8.8File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary co...
CVE-2023-45322MEDIUM6.5libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in ...
CVE-2023-45311CRITICAL9.8fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adv...
CVE-2023-3725CRITICAL9.8Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
CVE-2023-5452MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
CVE-2023-45303HIGH8.8ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A...
CVE-2023-45282HIGH7.5In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
CVE-2023-21291MEDIUM5.5In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing p...
CVE-2023-21266HIGH7.8In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a ...
CVE-2023-21253MEDIUM5.5In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could ...
CVE-2023-21252MEDIUM5.5In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to imp...
CVE-2023-21244MEDIUM6.7In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che...
CVE-2023-5366MEDIUM5.5A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op...
CVE-2023-5214CRITICAL9.8In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
CVE-2023-45239CRITICAL9.8A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled,...
CVE-2023-44384MEDIUM4.1Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now