2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0129HIGH8.8Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user...
CVE-2023-0128HIGH8.8Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convi...
CVE-2023-0162MEDIUM4.8The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type sett...
CVE-2023-22911MEDIUM6.1An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Wid...
CVE-2023-22909MEDIUM5.3An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Speci...
CVE-2023-22903CRITICAL9.8api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
CVE-2023-22320HIGH7.5OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a p...
CVE-2023-0023MEDIUM5.7In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, p...
CVE-2023-0022HIGH8.8SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious...
CVE-2023-0018MEDIUM6.1Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC ap...
CVE-2023-0017CRITICAL9.8An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to a...
CVE-2023-0016HIGH8.8SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of ...
CVE-2023-0015MEDIUM5.4In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return...
CVE-2023-0014CRITICAL9.8SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, ...
CVE-2023-0013MEDIUM6.1The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 75...
CVE-2023-0012MEDIUM6.7In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be abl...
CVE-2023-22899MEDIUM5.9Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive...
CVE-2023-22898MEDIUM6.5workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits...
CVE-2023-22895HIGH7.5The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an int...
CVE-2023-0125MEDIUM6.1A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnera...
CVE-2023-22477HIGH7.5Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of ser...
CVE-2023-22473LOW2.1Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker...
CVE-2023-22472HIGH8.8Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N...
CVE-2023-0036HIGH7.8platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulne...
CVE-2023-0035HIGH7.8softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now