2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48263 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48262 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48251 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard... |
| CVE-2023-48250 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple ... |
| CVE-2023-48245 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the applicati... |
| CVE-2023-31446 | CRITICAL | 9.8 | 61.1% | Jan 10, 2024 | In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config... |
| CVE-2023-7222 | CRITICAL | 9.8 | 1.3% | Jan 9, 2024 | A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability ... |
| CVE-2023-7221 | CRITICAL | 9.8 | 1.5% | Jan 9, 2024 | A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the fu... |
| CVE-2023-5376 | CRITICAL | 9.1 | 1.4% | Jan 9, 2024 | An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet ... |
| CVE-2023-5347 | CRITICAL | 9.1 | 1.3% | Jan 9, 2024 | An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows ... |
| CVE-2023-51438 | CRITICAL | 9.8 | 0.6% | Jan 9, 2024 | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on W... |
| CVE-2023-49621 | CRITICAL | 9.8 | 0.6% | Jan 9, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system sta... |
| CVE-2023-50585 | CRITICAL | 9.8 | 0.7% | Jan 9, 2024 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fun... |
| CVE-2023-49237 | CRITICAL | 9.8 | 18.6% | Jan 9, 2024 | An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system fun... |
| CVE-2023-49236 | CRITICAL | 9.8 | 1.2% | Jan 9, 2024 | A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command ... |
| CVE-2023-49235 | CRITICAL | 9.8 | 0.8% | Jan 9, 2024 | An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information... |
| CVE-2023-7220 | CRITICAL | 9.8 | 1.5% | Jan 9, 2024 | A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue i... |
| CVE-2023-7219 | CRITICAL | 9.8 | 1.3% | Jan 9, 2024 | A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulne... |
| CVE-2023-51717 | CRITICAL | 9.8 | 0.6% | Jan 9, 2024 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. |
| CVE-2023-49238 | CRITICAL | 9.8 | 0.8% | Jan 9, 2024 | In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain insta... |
| CVE-2023-26999 | CRITICAL | 9.8 | 1.4% | Jan 9, 2024 | An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of s... |
| CVE-2023-50643 | CRITICAL | 9.8 | 2.2% | Jan 9, 2024 | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode a... |
| CVE-2023-52200 | CRITICAL | 9.8 | 0.3% | Jan 8, 2024 | Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Memb... |
| CVE-2023-50982 | CRITICAL | 9 | 1.3% | Jan 8, 2024 | Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in... |
| CVE-2023-52225 | CRITICAL | 9.8 | 0.6% | Jan 8, 2024 | Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & A... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now