2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1988MEDIUM4.8A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected...
CVE-2023-1980MEDIUM6.5Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to c...
CVE-2023-1939MEDIUM4.3No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prio...
CVE-2023-22641MEDIUM5.4A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7...
CVE-2023-30465MEDIUM5.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-26847MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o...
CVE-2023-26846MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o...
CVE-2023-26845MEDIUM4.3A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via u...
CVE-2023-23277MEDIUM6.1Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML ...
CVE-2023-28828MEDIUM5.9A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Enti...
CVE-2023-27464MEDIUM5.3A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forg...
CVE-2023-23588MEDIUM6.3A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Stora...
CVE-2023-1975MEDIUM6.5Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-1974MEDIUM6.5Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-28368MEDIUM5.7TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH h...
CVE-2023-27520MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote una...
CVE-2023-25955MEDIUM5.5National land numerical information data conversion tool all versions improperly restricts XML external entity reference...
CVE-2023-24464MEDIUM5.4Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web managemen...
CVE-2023-23575MEDIUM4.3Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass...
CVE-2023-23572MEDIUM4.8Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated at...
CVE-2023-29189MEDIUM5.4SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 8...
CVE-2023-29187MEDIUM6.7A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Progr...
CVE-2023-29186MEDIUM6.5In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a ...
CVE-2023-29185MEDIUM6.5SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,...
CVE-2023-29112MEDIUM5.4The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now