2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37878HIGH8.8Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wi...
CVE-2023-37875MEDIUM5.4Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu...
CVE-2023-3039HIGH7.8 SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious ...
CVE-2023-26142MEDIUM6.1All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build he...
CVE-2023-40625MEDIUM5.4S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization...
CVE-2023-40624MEDIUM5.4SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 75...
CVE-2023-40623HIGH7.1SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory unde...
CVE-2023-40622CRITICAL9.9SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition a...
CVE-2023-40621MEDIUM6.3SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and ha...
CVE-2023-40309CRITICAL9.8SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization...
CVE-2023-4893MEDIUM5.4The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortco...
CVE-2023-4890MEDIUM5.4The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-acco...
CVE-2023-4887MEDIUM5.4The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor...
CVE-2023-4840MEDIUM5.4The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortco...
CVE-2023-42472HIGH7.3Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML inte...
CVE-2023-41369MEDIUM4.3The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an a...
CVE-2023-41368MEDIUM5.3The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to ...
CVE-2023-41367MEDIUM5.3Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) ...
CVE-2023-40308HIGH7.5SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a...
CVE-2023-37489MEDIUM5.3Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version ...
CVE-2023-32558HIGH7.5The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnera...
CVE-2023-32005MEDIUM5.3A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the...
CVE-2023-25519HIGH7.8 NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host m...
CVE-2023-4899HIGH8.8 SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
CVE-2023-4898HIGH7.5Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now