2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6727MEDIUM4.3Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access ...
CVE-2023-4958MEDIUM6.1In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowin...
CVE-2023-4932MEDIUM5.4SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` param...
CVE-2023-6547MEDIUM5.4Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions...
CVE-2023-49874MEDIUM4.3Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t...
CVE-2023-49809MEDIUM6.5Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul...
CVE-2023-49695MEDIUM6.8OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and...
CVE-2023-49563MEDIUM6.1Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a craf...
CVE-2023-46701MEDIUM5.3Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint ...
CVE-2023-48642MEDIUM5.4Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote a...
CVE-2023-41120MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41116MEDIUM4.3An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41115MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41114MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41113MEDIUM4.3An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-5536MEDIUM6.4A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the l...
CVE-2023-49587MEDIUM6.4SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which c...
CVE-2023-49584MEDIUM4.3SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_B...
CVE-2023-49577MEDIUM6.1The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not suffici...
CVE-2023-46219MEDIUM5.3When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent reque...
CVE-2023-49058MEDIUM5.3SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path informa...
CVE-2023-42932MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS ...
CVE-2023-42924MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app...
CVE-2023-42923MEDIUM5.3This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Bro...
CVE-2023-42922MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now