2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29444 | HIGH | 7.3 | 0.2% | Jan 10, 2024 | An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent... |
| CVE-2023-51970 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. |
| CVE-2023-51969 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo. |
| CVE-2023-51968 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo. |
| CVE-2023-51967 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo. |
| CVE-2023-51962 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo. |
| CVE-2023-50172 | MEDIUM | 5.3 | 0.8% | Jan 10, 2024 | A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN ... |
| CVE-2023-49864 | MEDIUM | 6.5 | 1.1% | Jan 10, 2024 | An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W... |
| CVE-2023-49863 | MEDIUM | 6.5 | 1.1% | Jan 10, 2024 | An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W... |
| CVE-2023-49862 | MEDIUM | 6.5 | 1.1% | Jan 10, 2024 | An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W... |
| CVE-2023-49810 | MEDIUM | 6.5 | 0.7% | Jan 10, 2024 | A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev maste... |
| CVE-2023-49738 | HIGH | 7.5 | 1.3% | Jan 10, 2024 | An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15f... |
| CVE-2023-49715 | HIGH | 8.8 | 1.4% | Jan 10, 2024 | A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo d... |
| CVE-2023-49599 | CRITICAL | 9.8 | 1.0% | Jan 10, 2024 | An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed... |
| CVE-2023-49589 | HIGH | 8.8 | 0.9% | Jan 10, 2024 | An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi... |
| CVE-2023-48730 | MEDIUM | 5.4 | 0.6% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo de... |
| CVE-2023-48728 | MEDIUM | 6.1 | 2.3% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.... |
| CVE-2023-47862 | CRITICAL | 9.8 | 1.1% | Jan 10, 2024 | A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit... |
| CVE-2023-47861 | MEDIUM | 5.4 | 0.8% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and... |
| CVE-2023-47171 | MEDIUM | 6.5 | 1.1% | Jan 10, 2024 | An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo... |
| CVE-2023-45139 | HIGH | 7.5 | 1.2% | Jan 10, 2024 | fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Inject... |
| CVE-2023-41056 | HIGH | 8.1 | 2.6% | Jan 10, 2024 | Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can res... |
| CVE-2023-6158 | MEDIUM | 6.5 | 0.6% | Jan 10, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2023-51965 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo. |
| CVE-2023-51964 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now