2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51963CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
CVE-2023-51960CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
CVE-2023-51959CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
CVE-2023-51958CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
CVE-2023-51957CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
CVE-2023-51956CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv
CVE-2023-51955CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
CVE-2023-51954CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
CVE-2023-51953CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
CVE-2023-51952CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
CVE-2023-51966CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
CVE-2023-51961CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
CVE-2023-5455MEDIUM6.5A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This f...
CVE-2023-51972CRITICAL9.8Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
CVE-2023-51971CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
CVE-2023-48266CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob...
CVE-2023-48265CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob...
CVE-2023-48264CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob...
CVE-2023-48263CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob...
CVE-2023-48262CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob...
CVE-2023-48261HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48260HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48259HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48258HIGH8.1The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP reque...
CVE-2023-48257HIGH8.8The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now