2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29111MEDIUM4.3The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized att...
CVE-2023-29110MEDIUM5.4The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP...
CVE-2023-29109MEDIUM4.6The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756...
CVE-2023-29108MEDIUM5.3The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vul...
CVE-2023-28763MEDIUM6.5SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attac...
CVE-2023-28761MEDIUM6.5In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make ...
CVE-2023-27897MEDIUM6.3In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a com...
CVE-2023-27499MEDIUM6.1SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.2...
CVE-2023-24527MEDIUM5.3SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities t...
CVE-2023-1903MEDIUM4.3SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticat...
CVE-2023-28341MEDIUM6.1Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauth...
CVE-2023-28340MEDIUM6.5Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
CVE-2023-24182MEDIUM5.4LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnera...
CVE-2023-29192MEDIUM4.3SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for ga...
CVE-2023-26467MEDIUM5.4A man in the middle can redirect traffic to a malicious server in a compromised configuration.
CVE-2023-24721MEDIUM5.4A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web script...
CVE-2023-1916MEDIUM6.1A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an...
CVE-2023-28093MEDIUM6.5A user with a compromised configuration can start an unsigned binary as a service.
CVE-2023-26773MEDIUM6.1Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privi...
CVE-2023-1971MEDIUM4.9** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994 tpAdmin 1.3.12....
CVE-2023-29376MEDIUM5.4An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2...
CVE-2023-25392MEDIUM5.9Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
CVE-2023-24181MEDIUM5.4LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vuln...
CVE-2023-1426MEDIUM6.5The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing a...
CVE-2023-1122MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which co...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now