2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21131 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitig... |
| CVE-2023-21130 | CRITICAL | 9.8 | 0.5% | Jun 15, 2023 | In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow.... |
| CVE-2023-21129 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while... |
| CVE-2023-21128 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a log... |
| CVE-2023-21127 | HIGH | 8.8 | 0.5% | Jun 15, 2023 | In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could... |
| CVE-2023-21126 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under S... |
| CVE-2023-21124 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to ... |
| CVE-2023-21123 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction f... |
| CVE-2023-21122 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for... |
| CVE-2023-21121 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connect... |
| CVE-2023-21120 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | In multiple functions of cdm_engine.cpp, there is a possible use-after-free due to improper locking. This could lead to ... |
| CVE-2023-21115 | HIGH | 8.8 | 0.1% | Jun 15, 2023 | In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used c... |
| CVE-2023-21108 | HIGH | 8.8 | 0.2% | Jun 15, 2023 | In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could ... |
| CVE-2023-21105 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This ... |
| CVE-2023-21101 | HIGH | 7 | 0.1% | Jun 15, 2023 | In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to... |
| CVE-2023-21095 | MEDIUM | 4.7 | 0.1% | Jun 15, 2023 | In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a rac... |
| CVE-2023-34833 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arb... |
| CVE-2023-34455 | HIGH | 7.5 | 1.8% | Jun 15, 2023 | snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal ... |
| CVE-2023-34880 | CRITICAL | 9.8 | 1.1% | Jun 15, 2023 | cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admi... |
| CVE-2023-34666 | MEDIUM | 6.1 | 0.7% | Jun 15, 2023 | Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to injec... |
| CVE-2023-34454 | HIGH | 7.5 | 1.5% | Jun 15, 2023 | snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur ... |
| CVE-2023-34453 | HIGH | 7.5 | 1.7% | Jun 15, 2023 | snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur ... |
| CVE-2023-34626 | MEDIUM | 4.3 | 0.5% | Jun 15, 2023 | Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function. |
| CVE-2023-27634 | HIGH | 8.8 | 0.3% | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability allows arbitrary file upload in Shingo Intrepidity plugin <= 1.5.1 versi... |
| CVE-2023-25055 | HIGH | 8.8 | 0.3% | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now