2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4909MEDIUM4.3Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfus...
CVE-2023-4908MEDIUM4.3Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to ...
CVE-2023-4907MEDIUM4.3Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to ...
CVE-2023-4906MEDIUM4.3Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass ...
CVE-2023-4905MEDIUM4.3Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof secur...
CVE-2023-4904MEDIUM4.3Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass...
CVE-2023-4903MEDIUM4.3Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote a...
CVE-2023-4902MEDIUM4.3Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof securit...
CVE-2023-4901MEDIUM4.3Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially...
CVE-2023-4900MEDIUM4.3Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker...
CVE-2023-41885MEDIUM5.3Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUs...
CVE-2023-4921HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local priv...
CVE-2023-4918HIGH8.8A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself throu...
CVE-2023-41331CRITICAL9.8SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefull...
CVE-2023-3712HIGH7.8Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page mod...
CVE-2023-3711HIGH8.8Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Fal...
CVE-2023-3710CRITICAL9.8Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec...
CVE-2023-39215MEDIUM6.5Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network acces...
CVE-2023-39208HIGH7.5Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c...
CVE-2023-39201MEDIUM6.7Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of p...
CVE-2023-21523MEDIUM5.4 A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and ...
CVE-2023-21520MEDIUM5.3 A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry...
CVE-2023-4501CRITICAL9.8User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL ...
CVE-2023-30962MEDIUM5.4The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed ...
CVE-2023-21522MEDIUM6.1 A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now