2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45316HIGH8.8Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a...
CVE-2023-41623HIGH7.2Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.ph...
CVE-2023-48642MEDIUM5.4Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote a...
CVE-2023-48641HIGH8.8Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authe...
CVE-2023-41120MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41119HIGH8.8An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41118HIGH8.8An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41117CRITICAL9.8An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41116MEDIUM4.3An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41115MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41114MEDIUM6.5An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-41113MEDIUM4.3An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-6709HIGH8.8Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-50424CRITICAL9.8SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, al...
CVE-2023-6542HIGH7.1Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and ca...
CVE-2023-5536MEDIUM6.4A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the l...
CVE-2023-50423CRITICAL9.8SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an...
CVE-2023-50422CRITICAL9.8SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17...
CVE-2023-49587MEDIUM6.4SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which c...
CVE-2023-49584MEDIUM4.3SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_B...
CVE-2023-49583CRITICAL9.8SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions a...
CVE-2023-49581CRITICAL9.4SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise b...
CVE-2023-49580HIGH7.3SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an...
CVE-2023-49578LOW3.5SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack f...
CVE-2023-49577MEDIUM6.1The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not suffici...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now