2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23673 | MEDIUM | 4.8 | 0.4% | May 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3.... |
| CVE-2023-32956 | CRITICAL | 9.8 | 1.5% | May 16, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI componen... |
| CVE-2023-32955 | HIGH | 8.1 | 1.3% | May 16, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client ... |
| CVE-2023-2161 | MEDIUM | 5.5 | 0.2% | May 16, 2023 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized rea... |
| CVE-2023-2710 | MEDIUM | 6.1 | 0.6% | May 16, 2023 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the sea... |
| CVE-2023-2708 | MEDIUM | 6.1 | 0.6% | May 16, 2023 | The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter i... |
| CVE-2023-29961 | CRITICAL | 9.8 | 1.2% | May 16, 2023 | D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup, |
| CVE-2023-31131 | CRITICAL | 9.1 | 0.7% | May 15, 2023 | Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Da... |
| CVE-2023-2700 | MEDIUM | 5.5 | 0.3% | May 15, 2023 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capab... |
| CVE-2023-2124 | HIGH | 7.8 | 0.5% | May 15, 2023 | An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image ... |
| CVE-2023-21118 | MEDIUM | 5.5 | 0.2% | May 15, 2023 | In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead... |
| CVE-2023-21117 | HIGH | 7.8 | 0.1% | May 15, 2023 | In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to registe... |
| CVE-2023-21116 | MEDIUM | 6.7 | 0.1% | May 15, 2023 | In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below syste... |
| CVE-2023-21112 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could l... |
| CVE-2023-21111 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services d... |
| CVE-2023-21110 | HIGH | 7.8 | 0.1% | May 15, 2023 | In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaust... |
| CVE-2023-21109 | HIGH | 7.8 | 0.1% | May 15, 2023 | In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error i... |
| CVE-2023-21107 | HIGH | 7.8 | 0.1% | May 15, 2023 | In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local esc... |
| CVE-2023-21106 | HIGH | 7.8 | 0.1% | May 15, 2023 | In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to loca... |
| CVE-2023-21104 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure w... |
| CVE-2023-21103 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to ... |
| CVE-2023-21102 | HIGH | 7.8 | 0.2% | May 15, 2023 | In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error ... |
| CVE-2023-20930 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resour... |
| CVE-2023-20914 | MEDIUM | 5.5 | 0.1% | May 15, 2023 | In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for th... |
| CVE-2023-20726 | LOW | 3.3 | 0.1% | May 15, 2023 | In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local informatio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now