2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49593HIGH7.2Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A ...
CVE-2023-49073HIGH7.2A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3....
CVE-2023-48270HIGH7.2A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4...
CVE-2023-47856HIGH7.2A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jung...
CVE-2023-47677HIGH8.8A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jun...
CVE-2023-46685CRITICAL9.8A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_1...
CVE-2023-45742HIGH7.2An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3...
CVE-2023-45215HIGH7.2A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SD...
CVE-2023-41251HIGH7.2A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4...
CVE-2023-34435HIGH7.2A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A spec...
CVE-2023-52340HIGH7.5The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed ea...
CVE-2023-52169HIGH8.2The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker ...
CVE-2023-52168HIGH8.4The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an at...
CVE-2023-24531CRITICAL9.8Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitiz...
CVE-2023-39324Rejected reason: reserved but not needed
CVE-2023-51778MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen...
CVE-2023-51777MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue sc...
CVE-2023-51776HIGH7.8Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute...
CVE-2023-41928MEDIUM5.3The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.
CVE-2023-41927MEDIUM5.3The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing...
CVE-2023-41926HIGH8.8The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled...
CVE-2023-41923HIGH7.2The user management section of the web application permits the creation of user accounts with excessively weak passwords...
CVE-2023-41922MEDIUM5.4A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation,...
CVE-2023-41921CRITICAL9.8A vulnerability allows attackers to download source code or an executable from a remote location and execute the code wi...
CVE-2023-41920CRITICAL9.8The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the devic...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now