2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22918 | MEDIUM | 6.5 | 0.8% | Apr 24, 2023 | A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-30613 | CRITICAL | 9 | 1.0% | Apr 24, 2023 | Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In ... |
| CVE-2023-30544 | MEDIUM | 4.3 | 0.4% | Apr 24, 2023 | Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th... |
| CVE-2023-26494 | MEDIUM | 6.1 | 0.6% | Apr 24, 2023 | lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login pa... |
| CVE-2023-26061 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard ... |
| CVE-2023-26060 | HIGH | 8.8 | 0.6% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Se... |
| CVE-2023-22917 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32,... |
| CVE-2023-22916 | HIGH | 8.1 | 0.7% | Apr 24, 2023 | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00... |
| CVE-2023-22915 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 ... |
| CVE-2023-22914 | HIGH | 7.2 | 1.0% | Apr 24, 2023 | A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 th... |
| CVE-2023-22913 | HIGH | 8.1 | 1.3% | Apr 24, 2023 | A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series... |
| CVE-2023-30776 | MEDIUM | 6.5 | 2.1% | Apr 24, 2023 | An authenticated user with specific data permissions could access database connections stored passwords by requesting a ... |
| CVE-2023-30622 | HIGH | 8.8 | 0.2% | Apr 24, 2023 | Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in cl... |
| CVE-2023-27524 | CRITICAL | 9.8 | 97.4% | Apr 24, 2023 | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered th... |
| CVE-2023-24823 | CRITICAL | 9.8 | 1.0% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-24822 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-24821 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-30378 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30376 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30375 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30373 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30372 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30371 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability. |
| CVE-2023-30370 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability. |
| CVE-2023-2251 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now