2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36766 | MEDIUM | 5.5 | 1.5% | Sep 12, 2023 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2023-36761 | MEDIUM | 6.5 | 19.0% | Sep 12, 2023 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2023-36759 | MEDIUM | 6.7 | 0.5% | Sep 12, 2023 | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2023-36736 | MEDIUM | 4.4 | 1.7% | Sep 12, 2023 | Microsoft Identity Linux Broker Remote Code Execution Vulnerability |
| CVE-2023-29463 | MEDIUM | 5.4 | 0.8% | Sep 12, 2023 | The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentic... |
| CVE-2023-34469 | MEDIUM | 4.6 | 0.2% | Sep 12, 2023 | AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical netwo... |
| CVE-2023-0119 | MEDIUM | 5.4 | 0.6% | Sep 12, 2023 | A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect fil... |
| CVE-2023-4913 | MEDIUM | 6.1 | 0.4% | Sep 12, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1. |
| CVE-2023-41013 | MEDIUM | 6.1 | 0.6% | Sep 12, 2023 | Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script ... |
| CVE-2023-40712 | MEDIUM | 6.5 | 1.5% | Sep 12, 2023 | Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to... |
| CVE-2023-40611 | MEDIUM | 4.3 | 1.3% | Sep 12, 2023 | Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized ... |
| CVE-2023-27169 | MEDIUM | 6.5 | 0.3% | Sep 12, 2023 | Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of... |
| CVE-2023-40725 | MEDIUM | 4 | 0.2% | Sep 12, 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsis... |
| CVE-2023-37875 | MEDIUM | 5.4 | 0.2% | Sep 12, 2023 | Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu... |
| CVE-2023-26142 | MEDIUM | 6.1 | 0.4% | Sep 12, 2023 | All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build he... |
| CVE-2023-40625 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization... |
| CVE-2023-40624 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 75... |
| CVE-2023-40621 | MEDIUM | 6.3 | 0.6% | Sep 12, 2023 | SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and ha... |
| CVE-2023-4893 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortco... |
| CVE-2023-4890 | MEDIUM | 5.4 | 0.4% | Sep 12, 2023 | The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-acco... |
| CVE-2023-4887 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor... |
| CVE-2023-4840 | MEDIUM | 5.4 | 0.5% | Sep 12, 2023 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortco... |
| CVE-2023-41369 | MEDIUM | 4.3 | 0.4% | Sep 12, 2023 | The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an a... |
| CVE-2023-41368 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to ... |
| CVE-2023-41367 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now