2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28764MEDIUM5.9SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext i...
CVE-2023-28762HIGH7.2SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administra...
CVE-2023-22813MEDIUM4.3 A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,...
CVE-2023-22710MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCom...
CVE-2023-24376MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions.
CVE-2023-23894MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Noti...
CVE-2023-31183MEDIUM6.1 Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using ...
CVE-2023-31182CRITICAL9.8 EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified meth...
CVE-2023-31181HIGH7.5 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal
CVE-2023-31180MEDIUM6.1 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - Reflected cross-site scripting (RXSS) through an unspecified reque...
CVE-2023-31179HIGH7.5AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the s...
CVE-2023-31178CRITICAL9.1AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified...
CVE-2023-31141MEDIUM5.9OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10...
CVE-2023-31140MEDIUM6.5OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a ...
CVE-2023-31133HIGH7.5Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid ...
CVE-2023-31129CRITICAL9.8The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message han...
CVE-2023-31127HIGH8.8libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPD...
CVE-2023-31125MEDIUM6.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2023-31123CRITICAL9.1`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior t...
CVE-2023-30334MEDIUM6.1AsmBB v2.9.1 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the MiniMag.asm and bbcod...
CVE-2023-2582MEDIUM6.1A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in...
CVE-2023-2513MEDIUM6.7A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode siz...
CVE-2023-2478MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start...
CVE-2023-24507CRITICAL9.8 AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecifie...
CVE-2023-24506HIGH7.5 Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now