2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24523HIGH8.8An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start S...
CVE-2023-24522MEDIUM6.1Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740...
CVE-2023-24521MEDIUM6.1Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 7...
CVE-2023-23860MEDIUM6.1SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ...
CVE-2023-23859MEDIUM6.1SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ...
CVE-2023-23858MEDIUM6.1Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 75...
CVE-2023-23856MEDIUM5.4In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json wit...
CVE-2023-23855MEDIUM5.4SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insuff...
CVE-2023-23854MEDIUM5.4SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not ...
CVE-2023-23853MEDIUM6.1An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740,...
CVE-2023-23852MEDIUM6.1SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting i...
CVE-2023-23851MEDIUM5.4SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload an...
CVE-2023-0025MEDIUM5.4SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which ...
CVE-2023-0024MEDIUM5.4SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which ...
CVE-2023-0020HIGH7.1SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensi...
CVE-2023-0019MEDIUM6.5In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1...
CVE-2023-22376MEDIUM6.1Reflected cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows...
CVE-2023-22375HIGH8.8Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions all...
CVE-2023-22370MEDIUM5.2Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a ...
CVE-2023-0655MEDIUM5.3SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error...
CVE-2023-24187HIGH7.8An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a ...
CVE-2023-0814MEDIUM6.5The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information...
CVE-2023-0804MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-s...
CVE-2023-0803MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-s...
CVE-2023-0802MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-s...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now