2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2938MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who...
CVE-2023-2937MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who...
CVE-2023-2936HIGH8.8Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corru...
CVE-2023-2935HIGH8.8Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corru...
CVE-2023-2934HIGH8.8Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exp...
CVE-2023-2933HIGH8.8Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-2932HIGH8.8Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-2931HIGH8.8Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-2930HIGH8.8Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install...
CVE-2023-2929HIGH8.8Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially expl...
CVE-2023-33181MEDIUM5.3Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will pr...
CVE-2023-33180MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and p...
CVE-2023-33179MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and p...
CVE-2023-0779HIGH7.7At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’...
CVE-2023-33178MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API...
CVE-2023-33177HIGH8.8Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially cra...
CVE-2023-32218MEDIUM6.1Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-31187MEDIUM6.5Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
CVE-2023-31186MEDIUM5.3Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
CVE-2023-31185HIGH7.5ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.
CVE-2023-31184HIGH7.8ROZCOM client CWE-798: Use of Hard-coded Credentials
CVE-2023-29735MEDIUM5.5An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database...
CVE-2023-29734CRITICAL9.8An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by ...
CVE-2023-29733HIGH7.8The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These...
CVE-2023-29732CRITICAL9.8SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now