2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42897MEDIUM4.6The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical...
CVE-2023-42894MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, mac...
CVE-2023-42891MEDIUM5.5An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ve...
CVE-2023-42890HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10...
CVE-2023-42886HIGH7.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.2, macOS Ventu...
CVE-2023-42884MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS...
CVE-2023-42883MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 a...
CVE-2023-42882HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may...
CVE-2023-42874LOW2.4This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields ma...
CVE-2023-42481HIGH8.1In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locke...
CVE-2023-42479MEDIUM6.1An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, ...
CVE-2023-42478HIGH7.6SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic ...
CVE-2023-42476MEDIUM6.8SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into We...
CVE-2023-40446HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPad...
CVE-2023-36654MEDIUM6.5Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated at...
CVE-2023-36652MEDIUM4.3A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated att...
CVE-2023-36651HIGH7.2Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as s...
CVE-2023-36650HIGH7.2A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands a...
CVE-2023-36649CRITICAL9.1Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows re...
CVE-2023-36648HIGH8.2Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticat...
CVE-2023-36647HIGH7.5A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows rem...
CVE-2023-36646HIGH8.8Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker wit...
CVE-2023-50245CRITICAL9.8OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overf...
CVE-2023-49805HIGH8.8Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with...
CVE-2023-49804HIGH7.8Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login pass...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now