2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-27400HIGH7.8A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application...
CVE-2023-27399HIGH7.8A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application...
CVE-2023-27398HIGH7.8A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application...
CVE-2023-27310HIGH8.8A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte...
CVE-2023-27309HIGH8.8A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte...
CVE-2023-25957HIGH7.5A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAM...
CVE-2023-27896HIGH7.5In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server...
CVE-2023-27893HIGH8.8An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP So...
CVE-2023-27500HIGH8.1An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-wr...
CVE-2023-27498HIGH7.2SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assign...
CVE-2023-27271HIGH7.5In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a mali...
CVE-2023-26459HIGH7.4Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 7...
CVE-2023-25617HIGH8.8SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, wh...
CVE-2023-25616HIGH8.8In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object executio...
CVE-2023-23857HIGH8.6Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to att...
CVE-2023-27581HIGH8.8github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workfl...
CVE-2023-0351HIGH8.8The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This...
CVE-2023-0348HIGH7.5Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an attacker to c...
CVE-2023-0346HIGH7.5Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox ...
CVE-2023-25803HIGH7.5Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a...
CVE-2023-25802HIGH7.5Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't ...
CVE-2023-0355HIGH7.5Akuvox E11 uses a hard-coded cryptographic key, which could allow an attacker to decrypt sensitive information.
CVE-2023-27010HIGH7.8Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all...
CVE-2023-25170HIGH8.8PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site reques...
CVE-2023-0477HIGH8.8The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any u...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now