2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-23863MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Black and White Digital Ltd TreePress – Easy Family Tr...
CVE-2023-32112MEDIUM5.5Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, S...
CVE-2023-31407MEDIUM5.4SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, r...
CVE-2023-31406MEDIUM6.1Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an ...
CVE-2023-31404MEDIUM5Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420...
CVE-2023-30743MEDIUM6.1Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757,...
CVE-2023-30742MEDIUM6.1SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF...
CVE-2023-30741MEDIUM6.1Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an ...
CVE-2023-29188MEDIUM5.4SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF ...
CVE-2023-28764MEDIUM5.9SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext i...
CVE-2023-22813MEDIUM4.3 A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,...
CVE-2023-22710MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCom...
CVE-2023-24376MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions.
CVE-2023-23894MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Noti...
CVE-2023-31183MEDIUM6.1 Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using ...
CVE-2023-31180MEDIUM6.1 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - Reflected cross-site scripting (RXSS) through an unspecified reque...
CVE-2023-31141MEDIUM5.9OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10...
CVE-2023-31140MEDIUM6.5OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a ...
CVE-2023-31125MEDIUM6.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2023-30334MEDIUM6.1AsmBB v2.9.1 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the MiniMag.asm and bbcod...
CVE-2023-2582MEDIUM6.1A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in...
CVE-2023-2513MEDIUM6.7A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode siz...
CVE-2023-2478MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start...
CVE-2023-21404MEDIUM5.3AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static R...
CVE-2023-30790MEDIUM5.4MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now