2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51963 | CRITICAL | 9.8 | 0.9% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. |
| CVE-2023-51960 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv. |
| CVE-2023-51959 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv. |
| CVE-2023-51958 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv. |
| CVE-2023-51957 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. |
| CVE-2023-51956 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv |
| CVE-2023-51955 | CRITICAL | 9.8 | 0.5% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. |
| CVE-2023-51954 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv. |
| CVE-2023-51953 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. |
| CVE-2023-51952 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. |
| CVE-2023-51966 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo. |
| CVE-2023-51961 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. |
| CVE-2023-5455 | MEDIUM | 6.5 | 0.6% | Jan 10, 2024 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This f... |
| CVE-2023-51972 | CRITICAL | 9.8 | 1.9% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. |
| CVE-2023-51971 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo. |
| CVE-2023-48266 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48265 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48264 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48263 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48262 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob... |
| CVE-2023-48261 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48260 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48259 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48258 | HIGH | 8.1 | 0.2% | Jan 10, 2024 | The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP reque... |
| CVE-2023-48257 | HIGH | 8.8 | 0.5% | Jan 10, 2024 | The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now