2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6727 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access ... |
| CVE-2023-4958 | MEDIUM | 6.1 | 0.5% | Dec 12, 2023 | In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowin... |
| CVE-2023-4932 | MEDIUM | 5.4 | 0.6% | Dec 12, 2023 | SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` param... |
| CVE-2023-6547 | MEDIUM | 5.4 | 0.3% | Dec 12, 2023 | Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions... |
| CVE-2023-49874 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t... |
| CVE-2023-49809 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul... |
| CVE-2023-49695 | MEDIUM | 6.8 | 0.9% | Dec 12, 2023 | OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and... |
| CVE-2023-49563 | MEDIUM | 6.1 | 0.5% | Dec 12, 2023 | Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a craf... |
| CVE-2023-46701 | MEDIUM | 5.3 | 0.4% | Dec 12, 2023 | Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint ... |
| CVE-2023-48642 | MEDIUM | 5.4 | 0.5% | Dec 12, 2023 | Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote a... |
| CVE-2023-41120 | MEDIUM | 6.5 | 0.5% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41116 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41115 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41114 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41113 | MEDIUM | 4.3 | 0.5% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-5536 | MEDIUM | 6.4 | 0.2% | Dec 12, 2023 | A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the l... |
| CVE-2023-49587 | MEDIUM | 6.4 | 0.4% | Dec 12, 2023 | SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which c... |
| CVE-2023-49584 | MEDIUM | 4.3 | 0.5% | Dec 12, 2023 | SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_B... |
| CVE-2023-49577 | MEDIUM | 6.1 | 0.4% | Dec 12, 2023 | The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not suffici... |
| CVE-2023-46219 | MEDIUM | 5.3 | 1.1% | Dec 12, 2023 | When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent reque... |
| CVE-2023-49058 | MEDIUM | 5.3 | 0.6% | Dec 12, 2023 | SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path informa... |
| CVE-2023-42932 | MEDIUM | 5.5 | 0.3% | Dec 12, 2023 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS ... |
| CVE-2023-42924 | MEDIUM | 5.5 | 0.3% | Dec 12, 2023 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app... |
| CVE-2023-42923 | MEDIUM | 5.3 | 0.7% | Dec 12, 2023 | This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Bro... |
| CVE-2023-42922 | MEDIUM | 5.5 | 0.3% | Dec 12, 2023 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now