2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45316 | HIGH | 8.8 | 0.3% | Dec 12, 2023 | Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a... |
| CVE-2023-41623 | HIGH | 7.2 | 0.8% | Dec 12, 2023 | Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.ph... |
| CVE-2023-48642 | MEDIUM | 5.4 | 0.5% | Dec 12, 2023 | Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote a... |
| CVE-2023-48641 | HIGH | 8.8 | 0.5% | Dec 12, 2023 | Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authe... |
| CVE-2023-41120 | MEDIUM | 6.5 | 0.5% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41119 | HIGH | 8.8 | 0.6% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41118 | HIGH | 8.8 | 0.8% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41117 | CRITICAL | 9.8 | 0.8% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41116 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41115 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41114 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-41113 | MEDIUM | 4.3 | 0.5% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-6709 | HIGH | 8.8 | 0.9% | Dec 12, 2023 | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2. |
| CVE-2023-50424 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, al... |
| CVE-2023-6542 | HIGH | 7.1 | 0.2% | Dec 12, 2023 | Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and ca... |
| CVE-2023-5536 | MEDIUM | 6.4 | 0.2% | Dec 12, 2023 | A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the l... |
| CVE-2023-50423 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an... |
| CVE-2023-50422 | CRITICAL | 9.8 | 1.4% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17... |
| CVE-2023-49587 | MEDIUM | 6.4 | 0.4% | Dec 12, 2023 | SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which c... |
| CVE-2023-49584 | MEDIUM | 4.3 | 0.5% | Dec 12, 2023 | SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_B... |
| CVE-2023-49583 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions a... |
| CVE-2023-49581 | CRITICAL | 9.4 | 0.5% | Dec 12, 2023 | SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise b... |
| CVE-2023-49580 | HIGH | 7.3 | 0.5% | Dec 12, 2023 | SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an... |
| CVE-2023-49578 | LOW | 3.5 | 0.3% | Dec 12, 2023 | SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack f... |
| CVE-2023-49577 | MEDIUM | 6.1 | 0.4% | Dec 12, 2023 | The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not suffici... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now