2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27268MEDIUM5.3SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowi...
CVE-2023-26461MEDIUM4.9SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges...
CVE-2023-26460MEDIUM5.3Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authenticatio...
CVE-2023-26459HIGH7.4Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 7...
CVE-2023-26457MEDIUM6.1SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scriptin...
CVE-2023-25618MEDIUM6.5SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,...
CVE-2023-25617HIGH8.8SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, wh...
CVE-2023-25616HIGH8.8In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object executio...
CVE-2023-25615MEDIUM4.9Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated h...
CVE-2023-24526MEDIUM5.3SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks f...
CVE-2023-23857HIGH8.6Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to att...
CVE-2023-0021MEDIUM6.1Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthentic...
CVE-2023-24279MEDIUM6.1A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attac...
CVE-2023-27587MEDIUM6.5ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing ...
CVE-2023-27582CRITICAL9.8maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a fu...
CVE-2023-27052CRITICAL9.8E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user...
CVE-2023-27583CRITICAL9.8PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used...
CVE-2023-27581HIGH8.8github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workfl...
CVE-2023-24368Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-0354CRITICAL9.1The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access se...
CVE-2023-0353CRITICAL9.8Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which cou...
CVE-2023-0352CRITICAL9.1The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the devi...
CVE-2023-0351HIGH8.8The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This...
CVE-2023-0350MEDIUM6.5Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u...
CVE-2023-0349CRITICAL9.1The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image and video. This could al...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now