2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23863 | MEDIUM | 4.8 | 0.4% | May 9, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Black and White Digital Ltd TreePress – Easy Family Tr... |
| CVE-2023-32112 | MEDIUM | 5.5 | 0.1% | May 9, 2023 | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, S... |
| CVE-2023-31407 | MEDIUM | 5.4 | 0.3% | May 9, 2023 | SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, r... |
| CVE-2023-31406 | MEDIUM | 6.1 | 0.5% | May 9, 2023 | Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an ... |
| CVE-2023-31404 | MEDIUM | 5 | 0.5% | May 9, 2023 | Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420... |
| CVE-2023-30743 | MEDIUM | 6.1 | 0.4% | May 9, 2023 | Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757,... |
| CVE-2023-30742 | MEDIUM | 6.1 | 0.4% | May 9, 2023 | SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF... |
| CVE-2023-30741 | MEDIUM | 6.1 | 0.4% | May 9, 2023 | Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an ... |
| CVE-2023-29188 | MEDIUM | 5.4 | 0.4% | May 9, 2023 | SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF ... |
| CVE-2023-28764 | MEDIUM | 5.9 | 0.5% | May 9, 2023 | SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext i... |
| CVE-2023-22813 | MEDIUM | 4.3 | 0.5% | May 8, 2023 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,... |
| CVE-2023-22710 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCom... |
| CVE-2023-24376 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions. |
| CVE-2023-23894 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Noti... |
| CVE-2023-31183 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using ... |
| CVE-2023-31180 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - Reflected cross-site scripting (RXSS) through an unspecified reque... |
| CVE-2023-31141 | MEDIUM | 5.9 | 0.5% | May 8, 2023 | OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10... |
| CVE-2023-31140 | MEDIUM | 6.5 | 0.9% | May 8, 2023 | OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a ... |
| CVE-2023-31125 | MEDIUM | 6.5 | 1.3% | May 8, 2023 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2023-30334 | MEDIUM | 6.1 | 0.6% | May 8, 2023 | AsmBB v2.9.1 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the MiniMag.asm and bbcod... |
| CVE-2023-2582 | MEDIUM | 6.1 | 0.6% | May 8, 2023 | A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in... |
| CVE-2023-2513 | MEDIUM | 6.7 | 0.2% | May 8, 2023 | A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode siz... |
| CVE-2023-2478 | MEDIUM | 6.5 | 5.0% | May 8, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start... |
| CVE-2023-21404 | MEDIUM | 5.3 | 0.3% | May 8, 2023 | AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static R... |
| CVE-2023-30790 | MEDIUM | 5.4 | 0.6% | May 8, 2023 | MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now