2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-22938MEDIUM4.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated ...
CVE-2023-22937MEDIUM4.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup ...
CVE-2023-22936MEDIUM6.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a ...
CVE-2023-22933MEDIUM6.1In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extens...
CVE-2023-22932MEDIUM6.1In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message i...
CVE-2023-22931MEDIUM4.3In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resou...
CVE-2023-0827MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17.
CVE-2023-25758MEDIUM4.2Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain th...
CVE-2023-25614MEDIUM6.1SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,...
CVE-2023-24529MEDIUM6.1Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 75...
CVE-2023-24528MEDIUM6.5SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to...
CVE-2023-24525MEDIUM5.4SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inpu...
CVE-2023-24524MEDIUM6.5SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated...
CVE-2023-24522MEDIUM6.1Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740...
CVE-2023-24521MEDIUM6.1Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 7...
CVE-2023-23860MEDIUM6.1SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ...
CVE-2023-23859MEDIUM6.1SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ...
CVE-2023-23858MEDIUM6.1Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 75...
CVE-2023-23856MEDIUM5.4In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json wit...
CVE-2023-23855MEDIUM5.4SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insuff...
CVE-2023-23854MEDIUM5.4SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not ...
CVE-2023-23853MEDIUM6.1An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740,...
CVE-2023-23852MEDIUM6.1SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting i...
CVE-2023-23851MEDIUM5.4SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload an...
CVE-2023-0025MEDIUM5.4SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now