2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22975MEDIUM6.1A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM...
CVE-2023-24157CRITICAL9.8A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allow...
CVE-2023-24156CRITICAL9.8A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows ...
CVE-2023-24155CRITICAL9.8TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the compon...
CVE-2023-24154CRITICAL9.8TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the fu...
CVE-2023-24153CRITICAL9.8A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1...
CVE-2023-24152CRITICAL9.8A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allo...
CVE-2023-24151CRITICAL9.8A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu ...
CVE-2023-24150CRITICAL9.8A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows...
CVE-2023-24149CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /e...
CVE-2023-24148CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in t...
CVE-2023-24147HIGH7.5TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in th...
CVE-2023-24146CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the...
CVE-2023-24145CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version paramete...
CVE-2023-24144CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the s...
CVE-2023-24143CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop param...
CVE-2023-24142CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize paramet...
CVE-2023-24141CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut para...
CVE-2023-24140CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum paramete...
CVE-2023-24139CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter i...
CVE-2023-24138CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in ...
CVE-2023-25139CRITICAL9.8sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct ...
CVE-2023-25136MEDIUM6.5OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i...
CVE-2023-25135CRITICAL9.8vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques...
CVE-2023-0124HIGH7.8Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now