2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30652HIGH7.8Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local...
CVE-2023-30651HIGH7.8Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local att...
CVE-2023-30650HIGH7.8Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attac...
CVE-2023-30649HIGH7.8Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to exec...
CVE-2023-30648MEDIUM5.5Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denia...
CVE-2023-30647HIGH7.8Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers...
CVE-2023-30646HIGH7.8Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to ...
CVE-2023-30645HIGH7.8Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to ...
CVE-2023-30644HIGH7.8Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to exec...
CVE-2023-30643HIGH7.1Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to ...
CVE-2023-30642MEDIUM5.5Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attack...
CVE-2023-30641MEDIUM4.3Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restri...
CVE-2023-30640LOW3.3Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to...
CVE-2023-3521MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
CVE-2023-29656MEDIUM6.1An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and lo...
CVE-2023-27225MEDIUM5.4A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 a...
CVE-2023-24256HIGH7.8An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privilege...
CVE-2023-3520MEDIUM4.6Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
CVE-2023-36828MEDIUM5.4Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does n...
CVE-2023-36827HIGH7.5Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ...
CVE-2023-36822HIGH8.1Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma ...
CVE-2023-36821HIGH8.8Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in ...
CVE-2023-36813HIGH8.8Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated...
CVE-2023-36809MEDIUM5.4Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Vers...
CVE-2023-36808CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now