2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24150 | CRITICAL | 9.8 | 2.1% | Feb 3, 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows... |
| CVE-2023-24149 | CRITICAL | 9.8 | 0.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /e... |
| CVE-2023-24148 | CRITICAL | 9.8 | 1.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in t... |
| CVE-2023-24146 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the... |
| CVE-2023-24145 | CRITICAL | 9.8 | 1.8% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version paramete... |
| CVE-2023-24144 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the s... |
| CVE-2023-24143 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop param... |
| CVE-2023-24142 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize paramet... |
| CVE-2023-24141 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut para... |
| CVE-2023-24140 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum paramete... |
| CVE-2023-24139 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter i... |
| CVE-2023-24138 | CRITICAL | 9.8 | 1.9% | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in ... |
| CVE-2023-25139 | CRITICAL | 9.8 | 1.4% | Feb 3, 2023 | sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct ... |
| CVE-2023-25135 | CRITICAL | 9.8 | 23.9% | Feb 3, 2023 | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques... |
| CVE-2023-0651 | CRITICAL | 9.8 | 0.8% | Feb 2, 2023 | A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the c... |
| CVE-2023-0641 | CRITICAL | 9.1 | 1.0% | Feb 2, 2023 | A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affe... |
| CVE-2023-0640 | CRITICAL | 9.8 | 6.5% | Feb 2, 2023 | A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown fun... |
| CVE-2023-0638 | CRITICAL | 9.8 | 2.9% | Feb 2, 2023 | A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects un... |
| CVE-2023-23076 | CRITICAL | 9.8 | 74.3% | Feb 1, 2023 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. |
| CVE-2023-22501 | CRITICAL | 9.1 | 16.0% | Feb 1, 2023 | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacke... |
| CVE-2023-24997 | CRITICAL | 9.8 | 1.4% | Feb 1, 2023 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In... |
| CVE-2023-0587 | CRITICAL | 9.1 | 59.6% | Feb 1, 2023 | A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length heade... |
| CVE-2023-23928 | CRITICAL | 9.8 | 0.5% | Feb 1, 2023 | reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This all... |
| CVE-2023-24241 | CRITICAL | 9.8 | 0.7% | Feb 1, 2023 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/l... |
| CVE-2023-23924 | CRITICAL | 9.8 | 3.6% | Feb 1, 2023 | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now