2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22918MEDIUM6.5A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 t...
CVE-2023-30613CRITICAL9Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In ...
CVE-2023-30544MEDIUM4.3Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th...
CVE-2023-26494MEDIUM6.1lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login pa...
CVE-2023-26061MEDIUM5.4An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard ...
CVE-2023-26060HIGH8.8An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Se...
CVE-2023-22917HIGH7.5A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32,...
CVE-2023-22916HIGH8.1The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00...
CVE-2023-22915HIGH7.5A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 ...
CVE-2023-22914HIGH7.2A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 th...
CVE-2023-22913HIGH8.1A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series...
CVE-2023-30776MEDIUM6.5An authenticated user with specific data permissions could access database connections stored passwords by requesting a ...
CVE-2023-30622HIGH8.8Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in cl...
CVE-2023-27524CRITICAL9.8Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered th...
CVE-2023-24823CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-24822HIGH7.5RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-24821HIGH7.5RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-30378CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
CVE-2023-30376CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
CVE-2023-30375CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
CVE-2023-30373CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
CVE-2023-30372CRITICAL9.8In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
CVE-2023-30371CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
CVE-2023-30370CRITICAL9.8In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
CVE-2023-2251HIGH7.5Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now