LiveActive security incident?Get immediate response
CVE archive

2023 CVE Archive

Browse CVE records published in 2023 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 30600 matching CVEs · Page 20 of 612.

Unknown · CVSS Not scored

CVE-2023-31868: Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS).

Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.

Published Jun 22, 2023 · Updated Jul 5, 2026

High · CVSS 7.2

CVE-2023-31742: There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006.

There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

Published May 22, 2023 · Updated Jul 5, 2026

High · CVSS 7.2

CVE-2023-31741: There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06.

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

Published May 23, 2023 · Updated Jul 5, 2026

Medium · CVSS 5.5

CVE-2023-29725: The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission...

The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.

Published Jun 2, 2023 · Updated Jul 5, 2026

High · CVSS 7.8

CVE-2023-29724: The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modi...

The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.

Published Jun 2, 2023 · Updated Jul 5, 2026

High · CVSS 7.5

CVE-2023-25262: Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).

Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).

Published Mar 28, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-25261: Certain Stimulsoft GmbH products are affected by: Remote Code Execution.

Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which reads or writes local directories and files. It is also possible for the attacker to prepare a report which has a variable that holds the gathered data and render it in the report.

Published Mar 27, 2023 · Updated Jul 5, 2026