2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36766MEDIUM5.5Microsoft Excel Information Disclosure Vulnerability
CVE-2023-36761MEDIUM6.5Microsoft Word Information Disclosure Vulnerability
CVE-2023-36759MEDIUM6.7Visual Studio Elevation of Privilege Vulnerability
CVE-2023-36736MEDIUM4.4Microsoft Identity Linux Broker Remote Code Execution Vulnerability
CVE-2023-29463MEDIUM5.4 The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentic...
CVE-2023-34469MEDIUM4.6 AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical netwo...
CVE-2023-0119MEDIUM5.4A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect fil...
CVE-2023-4913MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1.
CVE-2023-41013MEDIUM6.1Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script ...
CVE-2023-40712MEDIUM6.5Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to...
CVE-2023-40611MEDIUM4.3Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized ...
CVE-2023-27169MEDIUM6.5Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of...
CVE-2023-40725MEDIUM4A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsis...
CVE-2023-37875MEDIUM5.4Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu...
CVE-2023-26142MEDIUM6.1All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build he...
CVE-2023-40625MEDIUM5.4S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization...
CVE-2023-40624MEDIUM5.4SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 75...
CVE-2023-40621MEDIUM6.3SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and ha...
CVE-2023-4893MEDIUM5.4The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortco...
CVE-2023-4890MEDIUM5.4The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-acco...
CVE-2023-4887MEDIUM5.4The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor...
CVE-2023-4840MEDIUM5.4The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortco...
CVE-2023-41369MEDIUM4.3The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an a...
CVE-2023-41368MEDIUM5.3The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to ...
CVE-2023-41367MEDIUM5.3Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now