2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27389 | HIGH | 7.2 | 0.5% | Apr 11, 2023 | Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker wi... |
| CVE-2023-26593 | HIGH | 7.8 | 0.1% | Apr 11, 2023 | CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If... |
| CVE-2023-26588 | HIGH | 7.5 | 0.6% | Apr 11, 2023 | Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function o... |
| CVE-2023-25955 | MEDIUM | 5.5 | 0.2% | Apr 11, 2023 | National land numerical information data conversion tool all versions improperly restricts XML external entity reference... |
| CVE-2023-25950 | HIGH | 7.3 | 2.9% | Apr 11, 2023 | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to a... |
| CVE-2023-25755 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the... |
| CVE-2023-24544 | HIGH | 8.1 | 0.3% | Apr 11, 2023 | Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific f... |
| CVE-2023-24464 | MEDIUM | 5.4 | 0.4% | Apr 11, 2023 | Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web managemen... |
| CVE-2023-23575 | MEDIUM | 4.3 | 0.7% | Apr 11, 2023 | Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass... |
| CVE-2023-23572 | MEDIUM | 4.8 | 0.5% | Apr 11, 2023 | Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated at... |
| CVE-2023-22429 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an extern... |
| CVE-2023-22282 | HIGH | 7.3 | 0.2% | Apr 11, 2023 | WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service pa... |
| CVE-2023-29492 | CRITICAL | 9.8 | 2.7% | Apr 11, 2023 | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the servi... |
| CVE-2023-26122 | CRITICAL | 10 | 2.1% | Apr 11, 2023 | All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerabi... |
| CVE-2023-26121 | CRITICAL | 10 | 1.1% | Apr 11, 2023 | All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper s... |
| CVE-2023-29189 | MEDIUM | 5.4 | 0.4% | Apr 11, 2023 | SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 8... |
| CVE-2023-29187 | MEDIUM | 6.7 | 0.2% | Apr 11, 2023 | A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Progr... |
| CVE-2023-29186 | MEDIUM | 6.5 | 23.0% | Apr 11, 2023 | In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a ... |
| CVE-2023-29185 | MEDIUM | 6.5 | 0.6% | Apr 11, 2023 | SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,... |
| CVE-2023-29112 | MEDIUM | 5.4 | 0.3% | Apr 11, 2023 | The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or ... |
| CVE-2023-29111 | MEDIUM | 4.3 | 0.4% | Apr 11, 2023 | The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized att... |
| CVE-2023-29110 | MEDIUM | 5.4 | 0.3% | Apr 11, 2023 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP... |
| CVE-2023-29109 | MEDIUM | 4.6 | 0.3% | Apr 11, 2023 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756... |
| CVE-2023-29108 | MEDIUM | 5.3 | 0.4% | Apr 11, 2023 | The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vul... |
| CVE-2023-28765 | CRITICAL | 9.8 | 14.9% | Apr 11, 2023 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - version... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now