2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24180 | MEDIUM | 6.5 | 0.6% | Mar 14, 2023 | Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerabili... |
| CVE-2023-27462 | MEDIUM | 4.3 | 0.5% | Mar 14, 2023 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affecte... |
| CVE-2023-27895 | MEDIUM | 6.5 | 0.4% | Mar 14, 2023 | SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a ma... |
| CVE-2023-27894 | MEDIUM | 5.3 | 0.6% | Mar 14, 2023 | SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbi... |
| CVE-2023-27270 | MEDIUM | 6.5 | 0.6% | Mar 14, 2023 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,... |
| CVE-2023-27268 | MEDIUM | 5.3 | 0.4% | Mar 14, 2023 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowi... |
| CVE-2023-26461 | MEDIUM | 4.9 | 0.5% | Mar 14, 2023 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges... |
| CVE-2023-26460 | MEDIUM | 5.3 | 0.5% | Mar 14, 2023 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authenticatio... |
| CVE-2023-26457 | MEDIUM | 6.1 | 0.4% | Mar 14, 2023 | SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scriptin... |
| CVE-2023-25618 | MEDIUM | 6.5 | 0.6% | Mar 14, 2023 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,... |
| CVE-2023-25615 | MEDIUM | 4.9 | 0.5% | Mar 14, 2023 | Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated h... |
| CVE-2023-24526 | MEDIUM | 5.3 | 0.6% | Mar 14, 2023 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks f... |
| CVE-2023-0021 | MEDIUM | 6.1 | 0.5% | Mar 14, 2023 | Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthentic... |
| CVE-2023-24279 | MEDIUM | 6.1 | 0.6% | Mar 14, 2023 | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attac... |
| CVE-2023-27587 | MEDIUM | 6.5 | 3.9% | Mar 13, 2023 | ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing ... |
| CVE-2023-0350 | MEDIUM | 6.5 | 0.3% | Mar 13, 2023 | Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u... |
| CVE-2023-0347 | MEDIUM | 5.3 | 0.5% | Mar 13, 2023 | The Akuvox E11 Media Access Control (MAC) address, a primary identifier, combined with the Akuvox E11 IP address, could ... |
| CVE-2023-27580 | MEDIUM | 5.9 | 0.5% | Mar 13, 2023 | CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementa... |
| CVE-2023-0973 | MEDIUM | 5.5 | 0.2% | Mar 13, 2023 | STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker t... |
| CVE-2023-0844 | MEDIUM | 4.8 | 0.4% | Mar 13, 2023 | The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-p... |
| CVE-2023-0772 | MEDIUM | 6.5 | 0.8% | Mar 13, 2023 | The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some... |
| CVE-2023-0749 | MEDIUM | 6.5 | 0.7% | Mar 13, 2023 | The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually... |
| CVE-2023-0538 | MEDIUM | 5.4 | 0.4% | Mar 13, 2023 | The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes bef... |
| CVE-2023-0219 | MEDIUM | 5.4 | 0.5% | Mar 13, 2023 | The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored c... |
| CVE-2023-0172 | MEDIUM | 5.4 | 0.5% | Mar 13, 2023 | The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now