2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40020 | HIGH | 8.3 | 0.4% | Aug 14, 2023 | PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v... |
| CVE-2023-40013 | MEDIUM | 5.4 | 0.5% | Aug 14, 2023 | SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. ... |
| CVE-2023-39950 | MEDIUM | 5.2 | 0.4% | Aug 14, 2023 | efibootguard is a simple UEFI boot loader with support for safely switching between current and updated partition sets. ... |
| CVE-2023-39829 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWire... |
| CVE-2023-39828 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet fun... |
| CVE-2023-39827 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRul... |
| CVE-2023-38687 | MEDIUM | 5.4 | 0.5% | Aug 14, 2023 | Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML wit... |
| CVE-2023-21269 | HIGH | 7.8 | 0.1% | Aug 14, 2023 | In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back... |
| CVE-2023-21268 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. Th... |
| CVE-2023-21267 | MEDIUM | 5.5 | 0.1% | Aug 14, 2023 | In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning ... |
| CVE-2023-21265 | HIGH | 7.5 | 0.3% | Aug 14, 2023 | In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information d... |
| CVE-2023-21264 | MEDIUM | 6.7 | 0.2% | Aug 14, 2023 | In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check... |
| CVE-2023-21242 | CRITICAL | 9.8 | 0.4% | Aug 14, 2023 | In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to ... |
| CVE-2023-21140 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21134 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21133 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-21132 | MEDIUM | 6.8 | 0.1% | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss... |
| CVE-2023-20965 | CRITICAL | 9.8 | 0.6% | Aug 14, 2023 | In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic ... |
| CVE-2023-40024 | MEDIUM | 6.1 | 0.4% | Aug 14, 2023 | ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the... |
| CVE-2023-40023 | HIGH | 7.5 | 0.9% | Aug 14, 2023 | yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file incl... |
| CVE-2023-3721 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-3645 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, wh... |
| CVE-2023-3601 | MEDIUM | 4.3 | 0.4% | Aug 14, 2023 | The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that us... |
| CVE-2023-3435 | CRITICAL | 9.8 | 0.8% | Aug 14, 2023 | The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before usi... |
| CVE-2023-3328 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now