2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22975 | MEDIUM | 6.1 | 0.4% | Feb 3, 2023 | A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2023-24157 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allow... |
| CVE-2023-24156 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows ... |
| CVE-2023-24155 | CRITICAL | 9.8 | 0.9% | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the compon... |
| CVE-2023-24154 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the fu... |
| CVE-2023-24153 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1... |
| CVE-2023-24152 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allo... |
| CVE-2023-24151 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu ... |
| CVE-2023-24150 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows... |
| CVE-2023-24149 | CRITICAL | 9.8 | 0.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /e... |
| CVE-2023-24148 | CRITICAL | 9.8 | 1.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in t... |
| CVE-2023-24147 | HIGH | 7.5 | 0.7% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in th... |
| CVE-2023-24146 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the... |
| CVE-2023-24145 | CRITICAL | 9.8 | 1.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version paramete... |
| CVE-2023-24144 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the s... |
| CVE-2023-24143 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop param... |
| CVE-2023-24142 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize paramet... |
| CVE-2023-24141 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut para... |
| CVE-2023-24140 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum paramete... |
| CVE-2023-24139 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter i... |
| CVE-2023-24138 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in ... |
| CVE-2023-25139 | CRITICAL | 9.8 | 1.4% | Feb 3, 2023 | sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct ... |
| CVE-2023-25136 | MEDIUM | 6.5 | 90.0% | Feb 3, 2023 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i... |
| CVE-2023-25135 | CRITICAL | 9.8 | 23.9% | Feb 3, 2023 | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques... |
| CVE-2023-0124 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now