2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27268 | MEDIUM | 5.3 | 0.4% | Mar 14, 2023 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowi... |
| CVE-2023-26461 | MEDIUM | 4.9 | 0.5% | Mar 14, 2023 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges... |
| CVE-2023-26460 | MEDIUM | 5.3 | 0.5% | Mar 14, 2023 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authenticatio... |
| CVE-2023-26459 | HIGH | 7.4 | 0.4% | Mar 14, 2023 | Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 7... |
| CVE-2023-26457 | MEDIUM | 6.1 | 0.4% | Mar 14, 2023 | SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scriptin... |
| CVE-2023-25618 | MEDIUM | 6.5 | 0.6% | Mar 14, 2023 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,... |
| CVE-2023-25617 | HIGH | 8.8 | 0.9% | Mar 14, 2023 | SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, wh... |
| CVE-2023-25616 | HIGH | 8.8 | 0.9% | Mar 14, 2023 | In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object executio... |
| CVE-2023-25615 | MEDIUM | 4.9 | 0.5% | Mar 14, 2023 | Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated h... |
| CVE-2023-24526 | MEDIUM | 5.3 | 0.6% | Mar 14, 2023 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks f... |
| CVE-2023-23857 | HIGH | 8.6 | 0.5% | Mar 14, 2023 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to att... |
| CVE-2023-0021 | MEDIUM | 6.1 | 0.5% | Mar 14, 2023 | Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthentic... |
| CVE-2023-24279 | MEDIUM | 6.1 | 0.6% | Mar 14, 2023 | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attac... |
| CVE-2023-27587 | MEDIUM | 6.5 | 3.9% | Mar 13, 2023 | ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing ... |
| CVE-2023-27582 | CRITICAL | 9.8 | 1.0% | Mar 13, 2023 | maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a fu... |
| CVE-2023-27052 | CRITICAL | 9.8 | 0.8% | Mar 13, 2023 | E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user... |
| CVE-2023-27583 | CRITICAL | 9.8 | 0.9% | Mar 13, 2023 | PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used... |
| CVE-2023-27581 | HIGH | 8.8 | 1.6% | Mar 13, 2023 | github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workfl... |
| CVE-2023-24368 | — | — | — | Mar 13, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2023-0354 | CRITICAL | 9.1 | 0.6% | Mar 13, 2023 | The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access se... |
| CVE-2023-0353 | CRITICAL | 9.8 | 0.4% | Mar 13, 2023 | Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which cou... |
| CVE-2023-0352 | CRITICAL | 9.1 | 0.6% | Mar 13, 2023 | The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the devi... |
| CVE-2023-0351 | HIGH | 8.8 | 1.4% | Mar 13, 2023 | The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This... |
| CVE-2023-0350 | MEDIUM | 6.5 | 0.3% | Mar 13, 2023 | Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u... |
| CVE-2023-0349 | CRITICAL | 9.1 | 0.6% | Mar 13, 2023 | The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image and video. This could al... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now