2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37488 | MEDIUM | 6.1 | 0.3% | Aug 8, 2023 | In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, ... |
| CVE-2023-37487 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain op... |
| CVE-2023-37486 | HIGH | 7.5 | 0.4% | Aug 8, 2023 | Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an ... |
| CVE-2023-37484 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user prov... |
| CVE-2023-37483 | CRITICAL | 9.8 | 1.0% | Aug 8, 2023 | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbit... |
| CVE-2023-36926 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente... |
| CVE-2023-36923 | HIGH | 7.8 | 0.2% | Aug 8, 2023 | SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the... |
| CVE-2023-33993 | HIGH | 7.5 | 0.5% | Aug 8, 2023 | B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send craf... |
| CVE-2023-39530 | CRITICAL | 9.1 | 0.7% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the... |
| CVE-2023-39529 | CRITICAL | 9.1 | 0.6% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from th... |
| CVE-2023-39528 | HIGH | 8.6 | 0.6% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can b... |
| CVE-2023-39527 | MEDIUM | 6.1 | 0.4% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ... |
| CVE-2023-39526 | CRITICAL | 9.8 | 1.3% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ... |
| CVE-2023-39525 | CRITICAL | 9.1 | 0.7% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compro... |
| CVE-2023-39523 | HIGH | 8.8 | 2.4% | Aug 7, 2023 | ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 3... |
| CVE-2023-4201 | CRITICAL | 9.8 | 0.6% | Aug 7, 2023 | A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affec... |
| CVE-2023-39524 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product s... |
| CVE-2023-39520 | HIGH | 7.8 | 0.3% | Aug 7, 2023 | Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomat... |
| CVE-2023-38704 | CRITICAL | 9.8 | 0.8% | Aug 7, 2023 | import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works... |
| CVE-2023-4200 | CRITICAL | 9.8 | 0.6% | Aug 7, 2023 | A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulner... |
| CVE-2023-39550 | HIGH | 8.8 | 0.9% | Aug 7, 2023 | Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overf... |
| CVE-2023-39363 | MEDIUM | 5.9 | 0.7% | Aug 7, 2023 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0... |
| CVE-2023-39349 | HIGH | 8.1 | 0.8% | Aug 7, 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2,... |
| CVE-2023-38940 | CRITICAL | 9.8 | 0.7% | Aug 7, 2023 | Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid ... |
| CVE-2023-38939 | CRITICAL | 9.8 | 0.7% | Aug 7, 2023 | Tenda F1202 V1.2.0.9 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the mit_ssid parameter in the f... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now