2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33989HIGH8.1An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can ...
CVE-2023-33988MEDIUM6.1In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the C...
CVE-2023-33987CRITICAL9.4An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEB...
CVE-2023-31405MEDIUM5.3SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker...
CVE-2023-2079HIGH7.1The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to...
CVE-2023-2078MEDIUM4.3The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2023-37190MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary...
CVE-2023-37189MEDIUM4.8A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attack...
CVE-2023-37191MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary...
CVE-2023-3608HIGH8.8A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown proce...
CVE-2023-30963MEDIUM5.4A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Found...
CVE-2023-30960MEDIUM4.3A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resour...
CVE-2023-30956MEDIUM5.3A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submi...
CVE-2023-24490MEDIUM4.3Users with only access to launch VDA applications can launch an unauthorized desktop
CVE-2023-24489CRITICAL9.8A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul...
CVE-2023-3607HIGH8A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Exec...
CVE-2023-3606HIGH8.8A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part o...
CVE-2023-34432HIGH7.8A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This fl...
CVE-2023-24488MEDIUM6.1Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site script...
CVE-2023-24487HIGH7.5Arbitrary file read in Citrix ADC and Citrix Gateway 
CVE-2023-24486MEDIUM5.5A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious loca...
CVE-2023-22835HIGH7.7A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitti...
CVE-2023-3605CRITICAL9.1A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this v...
CVE-2023-34316HIGH7.5​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which c...
CVE-2023-30765CRITICAL9.8​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now