2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40020HIGH8.3PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v...
CVE-2023-40013MEDIUM5.4SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. ...
CVE-2023-39950MEDIUM5.2efibootguard is a simple UEFI boot loader with support for safely switching between current and updated partition sets. ...
CVE-2023-39829HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWire...
CVE-2023-39828HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet fun...
CVE-2023-39827HIGH7.5Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRul...
CVE-2023-38687MEDIUM5.4Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML wit...
CVE-2023-21269HIGH7.8In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back...
CVE-2023-21268MEDIUM5.5In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. Th...
CVE-2023-21267MEDIUM5.5In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning ...
CVE-2023-21265HIGH7.5In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information d...
CVE-2023-21264MEDIUM6.7In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check...
CVE-2023-21242CRITICAL9.8In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to ...
CVE-2023-21140MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21134MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21133MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-21132MEDIUM6.8In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss...
CVE-2023-20965CRITICAL9.8In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic ...
CVE-2023-40024MEDIUM6.1ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the...
CVE-2023-40023HIGH7.5yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file incl...
CVE-2023-3721MEDIUM4.8The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-3645MEDIUM4.8The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, wh...
CVE-2023-3601MEDIUM4.3The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that us...
CVE-2023-3435CRITICAL9.8The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before usi...
CVE-2023-3328MEDIUM4.8The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now