2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-23997HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.
CVE-2023-23731HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.
CVE-2023-23704HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions.
CVE-2023-23803HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions.
CVE-2023-23791HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.
CVE-2023-23792HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0 versions.
CVE-2023-36925HIGH7.2SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requ...
CVE-2023-36922HIGH8.8Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authentica...
CVE-2023-36921HIGH7.2SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. ...
CVE-2023-36917HIGH7.5SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked ...
CVE-2023-35874HIGH7.4SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRN...
CVE-2023-35870HIGH7.3When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 1...
CVE-2023-33990HIGH7.1SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing t...
CVE-2023-33989HIGH8.1An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can ...
CVE-2023-2079HIGH7.1The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to...
CVE-2023-3608HIGH8.8A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown proce...
CVE-2023-3607HIGH8A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Exec...
CVE-2023-3606HIGH8.8A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part o...
CVE-2023-34432HIGH7.8A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This fl...
CVE-2023-24487HIGH7.5Arbitrary file read in Citrix ADC and Citrix Gateway 
CVE-2023-22835HIGH7.7A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitti...
CVE-2023-34316HIGH7.5​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which c...
CVE-2023-34318HIGH7.8A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can...
CVE-2023-3579HIGH8.8A vulnerability, which was classified as problematic, has been found in HadSky 7.11.8. Affected by this issue is some un...
CVE-2023-3273HIGH7.5Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability o...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now