2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27389HIGH7.2Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker wi...
CVE-2023-26593HIGH7.8CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If...
CVE-2023-26588HIGH7.5Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function o...
CVE-2023-25955MEDIUM5.5National land numerical information data conversion tool all versions improperly restricts XML external entity reference...
CVE-2023-25950HIGH7.3HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to a...
CVE-2023-25755HIGH7.8Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the...
CVE-2023-24544HIGH8.1Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific f...
CVE-2023-24464MEDIUM5.4Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web managemen...
CVE-2023-23575MEDIUM4.3Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass...
CVE-2023-23572MEDIUM4.8Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated at...
CVE-2023-22429HIGH7.8Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an extern...
CVE-2023-22282HIGH7.3WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service pa...
CVE-2023-29492CRITICAL9.8Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the servi...
CVE-2023-26122CRITICAL10All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerabi...
CVE-2023-26121CRITICAL10All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper s...
CVE-2023-29189MEDIUM5.4SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 8...
CVE-2023-29187MEDIUM6.7A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Progr...
CVE-2023-29186MEDIUM6.5In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a ...
CVE-2023-29185MEDIUM6.5SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,...
CVE-2023-29112MEDIUM5.4The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or ...
CVE-2023-29111MEDIUM4.3The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized att...
CVE-2023-29110MEDIUM5.4The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP...
CVE-2023-29109MEDIUM4.6The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756...
CVE-2023-29108MEDIUM5.3The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vul...
CVE-2023-28765CRITICAL9.8An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - version...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now