2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40634 | HIGH | 7.8 | 0.1% | Oct 8, 2023 | In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with... |
| CVE-2023-40633 | MEDIUM | 5.5 | 0.1% | Oct 8, 2023 | In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with ... |
| CVE-2023-40632 | HIGH | 7.5 | 0.4% | Oct 8, 2023 | In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure... |
| CVE-2023-40631 | MEDIUM | 4.4 | 0.1% | Oct 8, 2023 | In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System exe... |
| CVE-2023-45199 | CRITICAL | 9.8 | 1.0% | Oct 7, 2023 | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. |
| CVE-2023-43615 | HIGH | 7.5 | 0.8% | Oct 7, 2023 | Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. |
| CVE-2023-5182 | MEDIUM | 5.5 | 0.2% | Oct 7, 2023 | Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use... |
| CVE-2023-36123 | HIGH | 7.8 | 0.7% | Oct 7, 2023 | Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to ex... |
| CVE-2023-44860 | HIGH | 7.5 | 19.5% | Oct 6, 2023 | An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization ... |
| CVE-2023-44061 | HIGH | 8.8 | 1.2% | Oct 6, 2023 | File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary co... |
| CVE-2023-45322 | MEDIUM | 6.5 | 0.8% | Oct 6, 2023 | libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in ... |
| CVE-2023-45311 | CRITICAL | 9.8 | 1.5% | Oct 6, 2023 | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adv... |
| CVE-2023-3725 | CRITICAL | 9.8 | 1.1% | Oct 6, 2023 | Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem |
| CVE-2023-5452 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. |
| CVE-2023-45303 | HIGH | 8.8 | 0.9% | Oct 6, 2023 | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A... |
| CVE-2023-45282 | HIGH | 7.5 | 0.9% | Oct 6, 2023 | In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action. |
| CVE-2023-21291 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing p... |
| CVE-2023-21266 | HIGH | 7.8 | 0.1% | Oct 6, 2023 | In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a ... |
| CVE-2023-21253 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could ... |
| CVE-2023-21252 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to imp... |
| CVE-2023-21244 | MEDIUM | 6.7 | 0.1% | Oct 6, 2023 | In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che... |
| CVE-2023-5366 | MEDIUM | 5.5 | 0.4% | Oct 6, 2023 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op... |
| CVE-2023-5214 | CRITICAL | 9.8 | 0.4% | Oct 6, 2023 | In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. |
| CVE-2023-45239 | CRITICAL | 9.8 | 1.8% | Oct 6, 2023 | A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled,... |
| CVE-2023-44384 | MEDIUM | 4.1 | 0.4% | Oct 6, 2023 | Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now