2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4909 | MEDIUM | 4.3 | 0.6% | Sep 12, 2023 | Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfus... |
| CVE-2023-4908 | MEDIUM | 4.3 | 0.6% | Sep 12, 2023 | Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to ... |
| CVE-2023-4907 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to ... |
| CVE-2023-4906 | MEDIUM | 4.3 | 0.6% | Sep 12, 2023 | Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass ... |
| CVE-2023-4905 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof secur... |
| CVE-2023-4904 | MEDIUM | 4.3 | 0.6% | Sep 12, 2023 | Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass... |
| CVE-2023-4903 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote a... |
| CVE-2023-4902 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof securit... |
| CVE-2023-4901 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially... |
| CVE-2023-4900 | MEDIUM | 4.3 | 0.7% | Sep 12, 2023 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker... |
| CVE-2023-41885 | MEDIUM | 5.3 | 0.5% | Sep 12, 2023 | Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUs... |
| CVE-2023-4921 | HIGH | 7.8 | 0.4% | Sep 12, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local priv... |
| CVE-2023-4918 | HIGH | 8.8 | 0.5% | Sep 12, 2023 | A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself throu... |
| CVE-2023-41331 | CRITICAL | 9.8 | 1.3% | Sep 12, 2023 | SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefull... |
| CVE-2023-3712 | HIGH | 7.8 | 0.5% | Sep 12, 2023 | Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page mod... |
| CVE-2023-3711 | HIGH | 8.8 | 0.9% | Sep 12, 2023 | Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Fal... |
| CVE-2023-3710 | CRITICAL | 9.8 | 33.1% | Sep 12, 2023 | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec... |
| CVE-2023-39215 | MEDIUM | 6.5 | 0.9% | Sep 12, 2023 | Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network acces... |
| CVE-2023-39208 | HIGH | 7.5 | 0.5% | Sep 12, 2023 | Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c... |
| CVE-2023-39201 | MEDIUM | 6.7 | 0.2% | Sep 12, 2023 | Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of p... |
| CVE-2023-21523 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and ... |
| CVE-2023-21520 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry... |
| CVE-2023-4501 | CRITICAL | 9.8 | 0.6% | Sep 12, 2023 | User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL ... |
| CVE-2023-30962 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed ... |
| CVE-2023-21522 | MEDIUM | 6.1 | 0.3% | Sep 12, 2023 | A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now