2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4583HIGH7.5When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then ...
CVE-2023-4582HIGH8.8Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when al...
CVE-2023-4581MEDIUM4.3Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be down...
CVE-2023-4580MEDIUM6.5Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sen...
CVE-2023-4579LOW3.1Search queries in the default search engine could appear to have been the currently navigated URL if the search query it...
CVE-2023-4578MEDIUM6.5When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErro...
CVE-2023-4577MEDIUM6.5When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to...
CVE-2023-4576HIGH8.6On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow ...
CVE-2023-4575MEDIUM6.5When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been cre...
CVE-2023-4574MEDIUM6.5When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been cr...
CVE-2023-4104MEDIUM5.5An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user ...
CVE-2023-4816HIGH8.8A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password ...
CVE-2023-4573MEDIUM6.5When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a u...
CVE-2023-42471CRITICAL9.8The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code...
CVE-2023-42470CRITICAL9.8The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a craft...
CVE-2023-35845MEDIUM4.7Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file use...
CVE-2023-40039CRITICAL9.8An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network...
CVE-2023-40040MEDIUM5.3An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacke...
CVE-2023-42467MEDIUM5.5QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_...
CVE-2023-4879MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
CVE-2023-4878MEDIUM5.4Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4873CRITICAL9.8A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intellige...
CVE-2023-4872CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Contact Manager App 1.0. This issue ...
CVE-2023-4871CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Contact Manager App 1.0. This vulnerability affects u...
CVE-2023-4870MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Contact Manager App 1.0. This affects an unkn...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now