2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28763 | MEDIUM | 6.5 | 0.6% | Apr 11, 2023 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attac... |
| CVE-2023-28761 | MEDIUM | 6.5 | 0.4% | Apr 11, 2023 | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make ... |
| CVE-2023-27897 | MEDIUM | 6.3 | 0.7% | Apr 11, 2023 | In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a com... |
| CVE-2023-27499 | MEDIUM | 6.1 | 0.4% | Apr 11, 2023 | SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.2... |
| CVE-2023-27497 | CRITICAL | 9.8 | 0.8% | Apr 11, 2023 | Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - ver... |
| CVE-2023-27267 | HIGH | 8.1 | 14.2% | Apr 11, 2023 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version... |
| CVE-2023-26458 | HIGH | 8.7 | 0.6% | Apr 11, 2023 | An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows ... |
| CVE-2023-24527 | MEDIUM | 5.3 | 0.5% | Apr 11, 2023 | SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities t... |
| CVE-2023-1903 | MEDIUM | 4.3 | 0.4% | Apr 11, 2023 | SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticat... |
| CVE-2023-28341 | MEDIUM | 6.1 | 98.8% | Apr 11, 2023 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauth... |
| CVE-2023-28340 | MEDIUM | 6.5 | 3.2% | Apr 11, 2023 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. |
| CVE-2023-27191 | HIGH | 7.5 | 1.1% | Apr 11, 2023 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPrefere... |
| CVE-2023-24182 | MEDIUM | 5.4 | 0.6% | Apr 11, 2023 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnera... |
| CVE-2023-29192 | MEDIUM | 4.3 | 0.4% | Apr 10, 2023 | SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for ga... |
| CVE-2023-26467 | MEDIUM | 5.4 | 0.6% | Apr 10, 2023 | A man in the middle can redirect traffic to a malicious server in a compromised configuration. |
| CVE-2023-24721 | MEDIUM | 5.4 | 0.5% | Apr 10, 2023 | A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web script... |
| CVE-2023-1916 | MEDIUM | 6.1 | 0.4% | Apr 10, 2023 | A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an... |
| CVE-2023-1668 | HIGH | 8.2 | 1.2% | Apr 10, 2023 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow ... |
| CVE-2023-29005 | HIGH | 7.5 | 0.6% | Apr 10, 2023 | Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. V... |
| CVE-2023-28093 | MEDIUM | 6.5 | 1.4% | Apr 10, 2023 | A user with a compromised configuration can start an unsigned binary as a service. |
| CVE-2023-27178 | CRITICAL | 9.8 | 1.4% | Apr 10, 2023 | An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary... |
| CVE-2023-27076 | CRITICAL | 9.8 | 22.9% | Apr 10, 2023 | Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the langua... |
| CVE-2023-26773 | MEDIUM | 6.1 | 0.9% | Apr 10, 2023 | Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privi... |
| CVE-2023-26466 | HIGH | 7.8 | 0.2% | Apr 10, 2023 | A user with non-Admin access can change a configuration file on the client to modify the Server URL. |
| CVE-2023-26495 | HIGH | 7.8 | 0.4% | Apr 10, 2023 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reus... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now