2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-24180MEDIUM6.5Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerabili...
CVE-2023-27462MEDIUM4.3A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affecte...
CVE-2023-27895MEDIUM6.5SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a ma...
CVE-2023-27894MEDIUM5.3SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbi...
CVE-2023-27270MEDIUM6.5SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,...
CVE-2023-27268MEDIUM5.3SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowi...
CVE-2023-26461MEDIUM4.9SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges...
CVE-2023-26460MEDIUM5.3Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authenticatio...
CVE-2023-26457MEDIUM6.1SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scriptin...
CVE-2023-25618MEDIUM6.5SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,...
CVE-2023-25615MEDIUM4.9Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated h...
CVE-2023-24526MEDIUM5.3SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks f...
CVE-2023-0021MEDIUM6.1Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthentic...
CVE-2023-24279MEDIUM6.1A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attac...
CVE-2023-27587MEDIUM6.5ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing ...
CVE-2023-0350MEDIUM6.5Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u...
CVE-2023-0347MEDIUM5.3The Akuvox E11 Media Access Control (MAC) address, a primary identifier, combined with the Akuvox E11 IP address, could ...
CVE-2023-27580MEDIUM5.9CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementa...
CVE-2023-0973MEDIUM5.5 STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker t...
CVE-2023-0844MEDIUM4.8The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-p...
CVE-2023-0772MEDIUM6.5The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some...
CVE-2023-0749MEDIUM6.5The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually...
CVE-2023-0538MEDIUM5.4The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes bef...
CVE-2023-0219MEDIUM5.4The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored c...
CVE-2023-0172MEDIUM5.4The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now