2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3512HIGH7.5Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit...
CVE-2023-37995HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ...
CVE-2023-2809CRITICAL9.8Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a ...
CVE-2023-2422HIGH7.1A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does ...
CVE-2023-25980HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Re...
CVE-2023-25788HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions.
CVE-2023-25489HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 ver...
CVE-2023-1584HIGH7.5A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an inse...
CVE-2023-5377HIGH7.1Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.
CVE-2023-5375MEDIUM6.1Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
CVE-2023-44272MEDIUM5.4A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant mes...
CVE-2023-5370MEDIUM5.5On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no spe...
CVE-2023-5369HIGH7.1Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input...
CVE-2023-5368MEDIUM6.5On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional...
CVE-2023-30738HIGH7.8An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro,...
CVE-2023-30737MEDIUM5.5Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive...
CVE-2023-30736MEDIUM5.4Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute java...
CVE-2023-30735LOW3.3Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access b...
CVE-2023-30734MEDIUM5.5Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive...
CVE-2023-30733HIGH7.8Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attac...
CVE-2023-30732LOW3.3Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial numbe...
CVE-2023-30731MEDIUM4.6Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to ins...
CVE-2023-30727HIGH7.5Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi an...
CVE-2023-30692HIGH7.8Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch pr...
CVE-2023-30690HIGH7.8Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileg...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now