2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21656HIGH7.8Memory corruption in WLAN HOST while receiving an WMI event from firmware.
CVE-2023-21632HIGH7.8Memory corruption in Automotive GPU while querying a gsl memory node.
CVE-2023-21628HIGH7.8Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2023-30915MEDIUM5.5In email service, there is a missing permission check. This could lead to local information disclosure with no additiona...
CVE-2023-30914MEDIUM5.5In email service, there is a missing permission check. This could lead to local information disclosure with no additiona...
CVE-2023-30866MEDIUM5.5In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit...
CVE-2023-30865MEDIUM5.5In dialer service, there is a missing permission check. This could lead to local information disclosure with no addition...
CVE-2023-30864HIGH7.8In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege ...
CVE-2023-30863HIGH7.8In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege ...
CVE-2023-2546HIGH8.8The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. ...
CVE-2023-32628CRITICAL9.8 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an a...
CVE-2023-32540CRITICAL9.8 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an ...
CVE-2023-22450HIGH7.2 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an att...
CVE-2023-34103MEDIUM5.4Avo is an open source ruby on rails admin panel creation framework. In affected versions some avo fields are vulnerable ...
CVE-2023-34102HIGH8.8Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to ope...
CVE-2023-3079HIGH8.8Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-3027HIGH7.8The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain so...
CVE-2023-24510HIGH7.5On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
CVE-2023-3111HIGH7.8A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. T...
CVE-2023-34097HIGH8.8hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed i...
CVE-2023-33410HIGH8.8Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vu...
CVE-2023-33409MEDIUM6.5Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/com...
CVE-2023-33408MEDIUM5.4Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation...
CVE-2023-31893HIGH7.5Telefnica Brasil Vivo Play (IPTV) Firmware: 2023.04.04.01.06.15 is vulnerable to Denial of Service (DoS) via DNS Recursi...
CVE-2023-29631CRITICAL9.8PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now