2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41990HIGH7.8The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, ma...
CVE-2023-40442LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Big Sur...
CVE-2023-40440HIGH7.5This issue was addressed with improved state management of S/MIME encrypted emails. This issue is fixed in macOS Montere...
CVE-2023-39069CRITICAL9.8An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Acti...
CVE-2023-41879HIGH7.5Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view...
CVE-2023-38878MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a rem...
CVE-2023-4897CRITICAL9.8Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
CVE-2023-35687HIGH7.8In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to ...
CVE-2023-35684HIGH8.8In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to...
CVE-2023-35683MEDIUM5.5In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injec...
CVE-2023-35682HIGH7.8In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a...
CVE-2023-35681CRITICAL9.8In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. Thi...
CVE-2023-35680MEDIUM5.5In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. Thi...
CVE-2023-35679MEDIUM5.5In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead ...
CVE-2023-35677MEDIUM5.5In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission c...
CVE-2023-35676HIGH7.8In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity la...
CVE-2023-35675MEDIUM5.5In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files play...
CVE-2023-35674HIGH7.8In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod...
CVE-2023-35673HIGH8.8In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could le...
CVE-2023-35671MEDIUM5.5In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read th...
CVE-2023-35670HIGH7.8In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private dire...
CVE-2023-35669HIGH7.8In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activ...
CVE-2023-35667HIGH7.8In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the...
CVE-2023-35666HIGH7.8In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead ...
CVE-2023-35665HIGH7.8In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now