2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49593 | HIGH | 7.2 | 1.1% | Jul 8, 2024 | Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A ... |
| CVE-2023-49073 | HIGH | 7.2 | 0.9% | Jul 8, 2024 | A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.... |
| CVE-2023-48270 | HIGH | 7.2 | 0.9% | Jul 8, 2024 | A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4... |
| CVE-2023-47856 | HIGH | 7.2 | 1.4% | Jul 8, 2024 | A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jung... |
| CVE-2023-47677 | HIGH | 8.8 | 0.4% | Jul 8, 2024 | A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jun... |
| CVE-2023-46685 | CRITICAL | 9.8 | 1.0% | Jul 8, 2024 | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_1... |
| CVE-2023-45742 | HIGH | 7.2 | 1.2% | Jul 8, 2024 | An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3... |
| CVE-2023-45215 | HIGH | 7.2 | 1.0% | Jul 8, 2024 | A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SD... |
| CVE-2023-41251 | HIGH | 7.2 | 1.3% | Jul 8, 2024 | A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4... |
| CVE-2023-34435 | HIGH | 7.2 | 0.5% | Jul 8, 2024 | A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A spec... |
| CVE-2023-52340 | HIGH | 7.5 | 0.9% | Jul 5, 2024 | The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed ea... |
| CVE-2023-52169 | HIGH | 8.2 | 1.0% | Jul 3, 2024 | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker ... |
| CVE-2023-52168 | HIGH | 8.4 | 0.3% | Jul 3, 2024 | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an at... |
| CVE-2023-24531 | CRITICAL | 9.8 | 0.8% | Jul 2, 2024 | Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitiz... |
| CVE-2023-39324 | — | — | — | Jul 2, 2024 | Rejected reason: reserved but not needed |
| CVE-2023-51778 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen... |
| CVE-2023-51777 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue sc... |
| CVE-2023-51776 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute... |
| CVE-2023-41928 | MEDIUM | 5.3 | 0.1% | Jul 2, 2024 | The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses. |
| CVE-2023-41927 | MEDIUM | 5.3 | 0.1% | Jul 2, 2024 | The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing... |
| CVE-2023-41926 | HIGH | 8.8 | 0.3% | Jul 2, 2024 | The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled... |
| CVE-2023-41923 | HIGH | 7.2 | 0.3% | Jul 2, 2024 | The user management section of the web application permits the creation of user accounts with excessively weak passwords... |
| CVE-2023-41922 | MEDIUM | 5.4 | 0.2% | Jul 2, 2024 | A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation,... |
| CVE-2023-41921 | CRITICAL | 9.8 | 0.3% | Jul 2, 2024 | A vulnerability allows attackers to download source code or an executable from a remote location and execute the code wi... |
| CVE-2023-41920 | CRITICAL | 9.8 | 0.4% | Jul 2, 2024 | The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the devic... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now