2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0129 | HIGH | 8.8 | 0.5% | Jan 10, 2023 | Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user... |
| CVE-2023-0128 | HIGH | 8.8 | 0.6% | Jan 10, 2023 | Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convi... |
| CVE-2023-0162 | MEDIUM | 4.8 | 0.5% | Jan 10, 2023 | The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type sett... |
| CVE-2023-22911 | MEDIUM | 6.1 | 0.6% | Jan 10, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Wid... |
| CVE-2023-22909 | MEDIUM | 5.3 | 0.9% | Jan 10, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Speci... |
| CVE-2023-22903 | CRITICAL | 9.8 | 0.7% | Jan 10, 2023 | api/views/user.py in LibrePhotos before e19e539 has incorrect access control. |
| CVE-2023-22320 | HIGH | 7.5 | 0.7% | Jan 10, 2023 | OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a p... |
| CVE-2023-0023 | MEDIUM | 5.7 | 0.5% | Jan 10, 2023 | In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, p... |
| CVE-2023-0022 | HIGH | 8.8 | 0.7% | Jan 10, 2023 | SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious... |
| CVE-2023-0018 | MEDIUM | 6.1 | 0.5% | Jan 10, 2023 | Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC ap... |
| CVE-2023-0017 | CRITICAL | 9.8 | 15.7% | Jan 10, 2023 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to a... |
| CVE-2023-0016 | HIGH | 8.8 | 0.6% | Jan 10, 2023 | SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of ... |
| CVE-2023-0015 | MEDIUM | 5.4 | 0.3% | Jan 10, 2023 | In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return... |
| CVE-2023-0014 | CRITICAL | 9.8 | 0.7% | Jan 10, 2023 | SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, ... |
| CVE-2023-0013 | MEDIUM | 6.1 | 0.4% | Jan 10, 2023 | The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 75... |
| CVE-2023-0012 | MEDIUM | 6.7 | 0.2% | Jan 10, 2023 | In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be abl... |
| CVE-2023-22899 | MEDIUM | 5.9 | 0.6% | Jan 10, 2023 | Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive... |
| CVE-2023-22898 | MEDIUM | 6.5 | 0.6% | Jan 10, 2023 | workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits... |
| CVE-2023-22895 | HIGH | 7.5 | 1.2% | Jan 10, 2023 | The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an int... |
| CVE-2023-0125 | MEDIUM | 6.1 | 0.5% | Jan 9, 2023 | A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnera... |
| CVE-2023-22477 | HIGH | 7.5 | 1.1% | Jan 9, 2023 | Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of ser... |
| CVE-2023-22473 | LOW | 2.1 | 0.6% | Jan 9, 2023 | Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker... |
| CVE-2023-22472 | HIGH | 8.8 | 0.2% | Jan 9, 2023 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N... |
| CVE-2023-0036 | HIGH | 7.8 | 0.2% | Jan 9, 2023 | platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulne... |
| CVE-2023-0035 | HIGH | 7.8 | 0.2% | Jan 9, 2023 | softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now