2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28763MEDIUM6.5SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attac...
CVE-2023-28761MEDIUM6.5In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make ...
CVE-2023-27897MEDIUM6.3In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a com...
CVE-2023-27499MEDIUM6.1SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.2...
CVE-2023-27497CRITICAL9.8Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - ver...
CVE-2023-27267HIGH8.1Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version...
CVE-2023-26458HIGH8.7An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows ...
CVE-2023-24527MEDIUM5.3SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities t...
CVE-2023-1903MEDIUM4.3SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticat...
CVE-2023-28341MEDIUM6.1Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauth...
CVE-2023-28340MEDIUM6.5Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
CVE-2023-27191HIGH7.5An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPrefere...
CVE-2023-24182MEDIUM5.4LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnera...
CVE-2023-29192MEDIUM4.3SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for ga...
CVE-2023-26467MEDIUM5.4A man in the middle can redirect traffic to a malicious server in a compromised configuration.
CVE-2023-24721MEDIUM5.4A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web script...
CVE-2023-1916MEDIUM6.1A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an...
CVE-2023-1668HIGH8.2A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow ...
CVE-2023-29005HIGH7.5Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. V...
CVE-2023-28093MEDIUM6.5A user with a compromised configuration can start an unsigned binary as a service.
CVE-2023-27178CRITICAL9.8An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary...
CVE-2023-27076CRITICAL9.8Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the langua...
CVE-2023-26773MEDIUM6.1Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privi...
CVE-2023-26466HIGH7.8A user with non-Admin access can change a configuration file on the client to modify the Server URL.
CVE-2023-26495HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reus...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now