2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37488MEDIUM6.1In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, ...
CVE-2023-37487MEDIUM5.3SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain op...
CVE-2023-37486HIGH7.5Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an ...
CVE-2023-37484MEDIUM5.3SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user prov...
CVE-2023-37483CRITICAL9.8SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbit...
CVE-2023-36926MEDIUM5.3Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente...
CVE-2023-36923HIGH7.8SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the...
CVE-2023-33993HIGH7.5B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send craf...
CVE-2023-39530CRITICAL9.1PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the...
CVE-2023-39529CRITICAL9.1PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from th...
CVE-2023-39528HIGH8.6PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can b...
CVE-2023-39527MEDIUM6.1PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ...
CVE-2023-39526CRITICAL9.8PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ...
CVE-2023-39525CRITICAL9.1PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compro...
CVE-2023-39523HIGH8.8ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 3...
CVE-2023-4201CRITICAL9.8A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affec...
CVE-2023-39524CRITICAL9.8PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product s...
CVE-2023-39520HIGH7.8Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomat...
CVE-2023-38704CRITICAL9.8import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works...
CVE-2023-4200CRITICAL9.8A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulner...
CVE-2023-39550HIGH8.8Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overf...
CVE-2023-39363MEDIUM5.9Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0...
CVE-2023-39349HIGH8.1Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2,...
CVE-2023-38940CRITICAL9.8Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid ...
CVE-2023-38939CRITICAL9.8Tenda F1202 V1.2.0.9 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the mit_ssid parameter in the f...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now