2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21131HIGH7.8In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitig...
CVE-2023-21130CRITICAL9.8In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow....
CVE-2023-21129HIGH7.8In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while...
CVE-2023-21128HIGH7.8In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a log...
CVE-2023-21127HIGH8.8In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could...
CVE-2023-21126HIGH7.8In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under S...
CVE-2023-21124HIGH7.8In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to ...
CVE-2023-21123HIGH7.8In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction f...
CVE-2023-21122HIGH7.8In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for...
CVE-2023-21121HIGH7.8In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connect...
CVE-2023-21120HIGH7.8In multiple functions of cdm_engine.cpp, there is a possible use-after-free due to improper locking. This could lead to ...
CVE-2023-21115HIGH8.8In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used c...
CVE-2023-21108HIGH8.8In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could ...
CVE-2023-21105MEDIUM5.5In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This ...
CVE-2023-21101HIGH7In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to...
CVE-2023-21095MEDIUM4.7In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a rac...
CVE-2023-34833MEDIUM6.1An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arb...
CVE-2023-34455HIGH7.5snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal ...
CVE-2023-34880CRITICAL9.8cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admi...
CVE-2023-34666MEDIUM6.1Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to injec...
CVE-2023-34454HIGH7.5snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur ...
CVE-2023-34453HIGH7.5snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur ...
CVE-2023-34626MEDIUM4.3Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
CVE-2023-27634HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability allows arbitrary file upload in Shingo Intrepidity plugin <= 1.5.1 versi...
CVE-2023-25055HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now