2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29444HIGH7.3An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent...
CVE-2023-51970CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
CVE-2023-51969CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.
CVE-2023-51968CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.
CVE-2023-51967CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.
CVE-2023-51962CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
CVE-2023-50172MEDIUM5.3A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN ...
CVE-2023-49864MEDIUM6.5An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W...
CVE-2023-49863MEDIUM6.5An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W...
CVE-2023-49862MEDIUM6.5An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W...
CVE-2023-49810MEDIUM6.5A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev maste...
CVE-2023-49738HIGH7.5An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15f...
CVE-2023-49715HIGH8.8A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo d...
CVE-2023-49599CRITICAL9.8An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed...
CVE-2023-49589HIGH8.8An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi...
CVE-2023-48730MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo de...
CVE-2023-48728MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11....
CVE-2023-47862CRITICAL9.8A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit...
CVE-2023-47861MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and...
CVE-2023-47171MEDIUM6.5An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo...
CVE-2023-45139HIGH7.5fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Inject...
CVE-2023-41056HIGH8.1Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can res...
CVE-2023-6158MEDIUM6.5The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2023-51965CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
CVE-2023-51964CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now