2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37878 | HIGH | 8.8 | 0.4% | Sep 12, 2023 | Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wi... |
| CVE-2023-37875 | MEDIUM | 5.4 | 0.2% | Sep 12, 2023 | Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu... |
| CVE-2023-3039 | HIGH | 7.8 | 0.2% | Sep 12, 2023 | SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious ... |
| CVE-2023-26142 | MEDIUM | 6.1 | 0.4% | Sep 12, 2023 | All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build he... |
| CVE-2023-40625 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization... |
| CVE-2023-40624 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 75... |
| CVE-2023-40623 | HIGH | 7.1 | 0.4% | Sep 12, 2023 | SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory unde... |
| CVE-2023-40622 | CRITICAL | 9.9 | 0.5% | Sep 12, 2023 | SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition a... |
| CVE-2023-40621 | MEDIUM | 6.3 | 0.6% | Sep 12, 2023 | SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and ha... |
| CVE-2023-40309 | CRITICAL | 9.8 | 0.7% | Sep 12, 2023 | SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization... |
| CVE-2023-4893 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortco... |
| CVE-2023-4890 | MEDIUM | 5.4 | 0.4% | Sep 12, 2023 | The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-acco... |
| CVE-2023-4887 | MEDIUM | 5.4 | 0.3% | Sep 12, 2023 | The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor... |
| CVE-2023-4840 | MEDIUM | 5.4 | 0.5% | Sep 12, 2023 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortco... |
| CVE-2023-42472 | HIGH | 7.3 | 0.5% | Sep 12, 2023 | Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML inte... |
| CVE-2023-41369 | MEDIUM | 4.3 | 0.4% | Sep 12, 2023 | The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an a... |
| CVE-2023-41368 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to ... |
| CVE-2023-41367 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) ... |
| CVE-2023-40308 | HIGH | 7.5 | 0.6% | Sep 12, 2023 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a... |
| CVE-2023-37489 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version ... |
| CVE-2023-32558 | HIGH | 7.5 | 1.5% | Sep 12, 2023 | The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnera... |
| CVE-2023-32005 | MEDIUM | 5.3 | 1.2% | Sep 12, 2023 | A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the... |
| CVE-2023-25519 | HIGH | 7.8 | 0.2% | Sep 12, 2023 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host m... |
| CVE-2023-4899 | HIGH | 8.8 | 0.6% | Sep 12, 2023 | SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. |
| CVE-2023-4898 | HIGH | 7.5 | 0.6% | Sep 12, 2023 | Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now