2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22938 | MEDIUM | 4.3 | 0.4% | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated ... |
| CVE-2023-22937 | MEDIUM | 4.3 | 0.4% | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup ... |
| CVE-2023-22936 | MEDIUM | 6.3 | 0.4% | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a ... |
| CVE-2023-22933 | MEDIUM | 6.1 | 0.8% | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extens... |
| CVE-2023-22932 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message i... |
| CVE-2023-22931 | MEDIUM | 4.3 | 0.4% | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resou... |
| CVE-2023-0827 | MEDIUM | 5.4 | 3.0% | Feb 14, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17. |
| CVE-2023-25758 | MEDIUM | 4.2 | 0.3% | Feb 14, 2023 | Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain th... |
| CVE-2023-25614 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,... |
| CVE-2023-24529 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 75... |
| CVE-2023-24528 | MEDIUM | 6.5 | 0.5% | Feb 14, 2023 | SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to... |
| CVE-2023-24525 | MEDIUM | 5.4 | 0.3% | Feb 14, 2023 | SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inpu... |
| CVE-2023-24524 | MEDIUM | 6.5 | 0.5% | Feb 14, 2023 | SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated... |
| CVE-2023-24522 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740... |
| CVE-2023-24521 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 7... |
| CVE-2023-23860 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ... |
| CVE-2023-23859 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an ... |
| CVE-2023-23858 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 75... |
| CVE-2023-23856 | MEDIUM | 5.4 | 0.3% | Feb 14, 2023 | In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json wit... |
| CVE-2023-23855 | MEDIUM | 5.4 | 0.3% | Feb 14, 2023 | SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insuff... |
| CVE-2023-23854 | MEDIUM | 5.4 | 0.5% | Feb 14, 2023 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not ... |
| CVE-2023-23853 | MEDIUM | 6.1 | 0.3% | Feb 14, 2023 | An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740,... |
| CVE-2023-23852 | MEDIUM | 6.1 | 0.4% | Feb 14, 2023 | SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting i... |
| CVE-2023-23851 | MEDIUM | 5.4 | 0.3% | Feb 14, 2023 | SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload an... |
| CVE-2023-0025 | MEDIUM | 5.4 | 0.3% | Feb 14, 2023 | SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now