2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21647MEDIUM6.5Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
CVE-2023-21643HIGH7.8Memory corruption due to untrusted pointer dereference in automotive during system call.
CVE-2023-21627HIGH7.8Memory corruption in Trusted Execution Environment while calling service API with invalid address.
CVE-2023-21626HIGH7.1Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2023-21625HIGH7.5Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
CVE-2023-4009HIGH7.2In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with proje...
CVE-2023-3898CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mAyaNet E-Commerce...
CVE-2023-37570HIGH8.8This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing th...
CVE-2023-37569HIGH8.8This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping compo...
CVE-2023-3573HIGH8.8In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use ...
CVE-2023-3572CRITICAL10In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an ...
CVE-2023-3571HIGH8.8In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use ...
CVE-2023-3570HIGH8.8In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use ...
CVE-2023-3569MEDIUM4.9In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior...
CVE-2023-3526CRITICAL9.6In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior ...
CVE-2023-39978LOW3.3ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
CVE-2023-39977Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3268. Reason: This candidate is a reservation du...
CVE-2023-39976CRITICAL9.8log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not consi...
CVE-2023-39440MEDIUM4.4In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain sp...
CVE-2023-39439CRITICAL9.8SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into ...
CVE-2023-39437MEDIUM5.4SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or ap...
CVE-2023-39436MEDIUM5.8SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker t...
CVE-2023-37492MEDIUM6.5SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASI...
CVE-2023-37491HIGH8.8The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64...
CVE-2023-37490CRITICAL9SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now