2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3290MEDIUM5A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the s...
CVE-2023-3289MEDIUM6.5A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (incl...
CVE-2023-3288HIGH8.8A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the syste...
CVE-2023-3287HIGH8.8A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system...
CVE-2023-3286MEDIUM6.5A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in th...
CVE-2023-38055HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete t...
CVE-2023-38054HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete...
CVE-2023-38053HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete...
CVE-2023-38052HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a hig...
CVE-2023-38051HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or del...
CVE-2023-38050HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a...
CVE-2023-38049HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or ...
CVE-2023-38048HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete...
CVE-2023-38047HIGH8.1A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delet...
CVE-2023-3285HIGH7.7A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the sys...
CVE-2023-50383HIGH7.2Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11....
CVE-2023-50382HIGH7.2Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11....
CVE-2023-50381HIGH7.2Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11....
CVE-2023-50330HIGH7.2A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.1...
CVE-2023-50244HIGH7.2Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v...
CVE-2023-50243HIGH7.2Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v...
CVE-2023-50240HIGH7.2Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819...
CVE-2023-50239HIGH7.2Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819...
CVE-2023-49867HIGH7.2A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.1...
CVE-2023-49595HIGH7.2A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jun...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now