2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21255HIGH7.8In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to loc...
CVE-2023-21254HIGH7.8In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the ...
CVE-2023-21251HIGH7.3In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper in...
CVE-2023-21250CRITICAL9.8In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2023-21249MEDIUM5.5In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a p...
CVE-2023-21248HIGH7.8In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device ...
CVE-2023-21247HIGH7.8In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a de...
CVE-2023-21246LOW3.3In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to ...
CVE-2023-21245HIGH7.8In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the loc...
CVE-2023-21243MEDIUM5.5In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file...
CVE-2023-21241HIGH7.8In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lea...
CVE-2023-21240MEDIUM5.5In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of s...
CVE-2023-21239MEDIUM5.5In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused d...
CVE-2023-21238MEDIUM5.5In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could ...
CVE-2023-21145HIGH7.8In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due t...
CVE-2023-20942MEDIUM5.5In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy...
CVE-2023-20918CRITICAL9.8In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused dep...
CVE-2023-33274CRITICAL9.8The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users ...
CVE-2023-26564CRITICAL9.8The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As...
CVE-2023-26563CRITICAL9.8The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an...
CVE-2023-3635HIGH7.5GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to deni...
CVE-2023-3644CRITICAL9.8A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. Th...
CVE-2023-3643CRITICAL9.8A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown par...
CVE-2023-3642MEDIUM6.1A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issu...
CVE-2023-3641MEDIUM6.1A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now