2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23673MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3....
CVE-2023-32956CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI componen...
CVE-2023-32955HIGH8.1Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client ...
CVE-2023-2161MEDIUM5.5 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized rea...
CVE-2023-2710MEDIUM6.1The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the sea...
CVE-2023-2708MEDIUM6.1The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter i...
CVE-2023-29961CRITICAL9.8D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
CVE-2023-31131CRITICAL9.1Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Da...
CVE-2023-2700MEDIUM5.5A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capab...
CVE-2023-2124HIGH7.8An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image ...
CVE-2023-21118MEDIUM5.5In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead...
CVE-2023-21117HIGH7.8In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to registe...
CVE-2023-21116MEDIUM6.7In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below syste...
CVE-2023-21112MEDIUM5.5In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could l...
CVE-2023-21111MEDIUM5.5In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services d...
CVE-2023-21110HIGH7.8In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaust...
CVE-2023-21109HIGH7.8In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error i...
CVE-2023-21107HIGH7.8In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local esc...
CVE-2023-21106HIGH7.8In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to loca...
CVE-2023-21104MEDIUM5.5In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure w...
CVE-2023-21103MEDIUM5.5In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to ...
CVE-2023-21102HIGH7.8In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error ...
CVE-2023-20930MEDIUM5.5In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resour...
CVE-2023-20914MEDIUM5.5In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for th...
CVE-2023-20726LOW3.3In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local informatio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now