2023 CVE Vulnerabilities
31,250 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27400 | HIGH | 7.8 | 0.2% | Mar 14, 2023 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application... |
| CVE-2023-27399 | HIGH | 7.8 | 0.2% | Mar 14, 2023 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application... |
| CVE-2023-27398 | HIGH | 7.8 | 0.2% | Mar 14, 2023 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application... |
| CVE-2023-27310 | HIGH | 8.8 | 0.6% | Mar 14, 2023 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte... |
| CVE-2023-27309 | HIGH | 8.8 | 0.5% | Mar 14, 2023 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte... |
| CVE-2023-25957 | HIGH | 7.5 | 0.6% | Mar 14, 2023 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAM... |
| CVE-2023-27896 | HIGH | 7.5 | 0.5% | Mar 14, 2023 | In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server... |
| CVE-2023-27893 | HIGH | 8.8 | 1.2% | Mar 14, 2023 | An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP So... |
| CVE-2023-27500 | HIGH | 8.1 | 1.0% | Mar 14, 2023 | An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-wr... |
| CVE-2023-27498 | HIGH | 7.2 | 0.5% | Mar 14, 2023 | SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assign... |
| CVE-2023-27271 | HIGH | 7.5 | 0.6% | Mar 14, 2023 | In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a mali... |
| CVE-2023-26459 | HIGH | 7.4 | 0.4% | Mar 14, 2023 | Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 7... |
| CVE-2023-25617 | HIGH | 8.8 | 0.9% | Mar 14, 2023 | SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, wh... |
| CVE-2023-25616 | HIGH | 8.8 | 0.9% | Mar 14, 2023 | In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object executio... |
| CVE-2023-23857 | HIGH | 8.6 | 0.5% | Mar 14, 2023 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to att... |
| CVE-2023-27581 | HIGH | 8.8 | 1.6% | Mar 13, 2023 | github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workfl... |
| CVE-2023-0351 | HIGH | 8.8 | 1.4% | Mar 13, 2023 | The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This... |
| CVE-2023-0348 | HIGH | 7.5 | 0.5% | Mar 13, 2023 | Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an attacker to c... |
| CVE-2023-0346 | HIGH | 7.5 | 0.6% | Mar 13, 2023 | Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox ... |
| CVE-2023-25803 | HIGH | 7.5 | 1.2% | Mar 13, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a... |
| CVE-2023-25802 | HIGH | 7.5 | 1.0% | Mar 13, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't ... |
| CVE-2023-0355 | HIGH | 7.5 | 0.5% | Mar 13, 2023 | Akuvox E11 uses a hard-coded cryptographic key, which could allow an attacker to decrypt sensitive information. |
| CVE-2023-27010 | HIGH | 7.8 | 1.0% | Mar 13, 2023 | Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all... |
| CVE-2023-25170 | HIGH | 8.8 | 0.2% | Mar 13, 2023 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site reques... |
| CVE-2023-0477 | HIGH | 8.8 | 1.6% | Mar 13, 2023 | The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any u... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now