2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29752 | HIGH | 7.8 | 0.4% | Jun 9, 2023 | An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privileg... |
| CVE-2023-29749 | HIGH | 7.8 | 0.4% | Jun 9, 2023 | An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks ... |
| CVE-2023-2455 | MEDIUM | 5.4 | 0.7% | Jun 9, 2023 | Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied... |
| CVE-2023-2454 | HIGH | 7.2 | 1.2% | Jun 9, 2023 | schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could perm... |
| CVE-2023-29714 | MEDIUM | 6.1 | 0.7% | Jun 9, 2023 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via t... |
| CVE-2023-29713 | MEDIUM | 6.1 | 0.7% | Jun 9, 2023 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a... |
| CVE-2023-27706 | HIGH | 7.1 | 0.6% | Jun 9, 2023 | Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, ac... |
| CVE-2023-34245 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | @udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected... |
| CVE-2023-34100 | MEDIUM | 6.5 | 0.4% | Jun 9, 2023 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value fro... |
| CVE-2023-33557 | HIGH | 8.8 | 0.8% | Jun 9, 2023 | Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php. |
| CVE-2023-30262 | HIGH | 8.8 | 0.8% | Jun 9, 2023 | An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a r... |
| CVE-2023-29712 | MEDIUM | 6.1 | 0.9% | Jun 9, 2023 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a... |
| CVE-2023-2121 | MEDIUM | 5.4 | 0.4% | Jun 9, 2023 | Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI throu... |
| CVE-2023-3184 | MEDIUM | 4.8 | 2.3% | Jun 9, 2023 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affec... |
| CVE-2023-3183 | MEDIUM | 5.4 | 0.6% | Jun 9, 2023 | A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affec... |
| CVE-2023-2286 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. T... |
| CVE-2023-2285 | MEDIUM | 4.3 | 0.2% | Jun 9, 2023 | The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2023-2284 | MEDIUM | 4.3 | 0.4% | Jun 9, 2023 | The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2023-2261 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ... |
| CVE-2023-32732 | MEDIUM | 5.3 | 0.5% | Jun 9, 2023 | gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC se... |
| CVE-2023-32731 | HIGH | 7.5 | 0.5% | Jun 9, 2023 | When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused a... |
| CVE-2023-1428 | HIGH | 7.5 | 0.4% | Jun 9, 2023 | There exists an vulnerability causing an abort() to be called in gRPC. The following headers cause gRPC's C++ implement... |
| CVE-2023-0342 | MEDIUM | 5.3 | 0.9% | Jun 9, 2023 | MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not inc... |
| CVE-2023-34364 | CRITICAL | 9.8 | 1.6% | Jun 9, 2023 | A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large v... |
| CVE-2023-34363 | MEDIUM | 5.9 | 0.3% | Jun 9, 2023 | An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now