2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50585 | CRITICAL | 9.8 | 0.7% | Jan 9, 2024 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fun... |
| CVE-2023-49237 | CRITICAL | 9.8 | 18.6% | Jan 9, 2024 | An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system fun... |
| CVE-2023-49236 | CRITICAL | 9.8 | 1.2% | Jan 9, 2024 | A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command ... |
| CVE-2023-49235 | CRITICAL | 9.8 | 0.8% | Jan 9, 2024 | An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information... |
| CVE-2023-7220 | CRITICAL | 9.8 | 1.5% | Jan 9, 2024 | A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue i... |
| CVE-2023-6147 | MEDIUM | 6.5 | 0.5% | Jan 9, 2024 | Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu... |
| CVE-2023-6842 | MEDIUM | 4.8 | 0.3% | Jan 9, 2024 | The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress i... |
| CVE-2023-6830 | MEDIUM | 6.1 | 0.4% | Jan 9, 2024 | The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu... |
| CVE-2023-50932 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, th... |
| CVE-2023-50931 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the... |
| CVE-2023-50930 | HIGH | 7.1 | 0.2% | Jan 9, 2024 | An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the conf... |
| CVE-2023-7219 | CRITICAL | 9.8 | 1.3% | Jan 9, 2024 | A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulne... |
| CVE-2023-6788 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2023-6594 | MEDIUM | 4.8 | 0.3% | Jan 9, 2024 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti... |
| CVE-2023-51717 | CRITICAL | 9.8 | 0.6% | Jan 9, 2024 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. |
| CVE-2023-49238 | CRITICAL | 9.8 | 0.8% | Jan 9, 2024 | In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain insta... |
| CVE-2023-39336 | HIGH | 8.8 | 10.0% | Jan 9, 2024 | An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker wi... |
| CVE-2023-36629 | MEDIUM | 5.5 | 0.4% | Jan 9, 2024 | The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read. |
| CVE-2023-27098 | HIGH | 7.5 | 0.5% | Jan 9, 2024 | TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel. |
| CVE-2023-27000 | MEDIUM | 6.1 | 0.7% | Jan 9, 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-26999 | CRITICAL | 9.8 | 1.4% | Jan 9, 2024 | An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of s... |
| CVE-2023-26998 | MEDIUM | 5.4 | 0.7% | Jan 9, 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-50643 | CRITICAL | 9.8 | 2.2% | Jan 9, 2024 | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode a... |
| CVE-2023-46906 | MEDIUM | 4.9 | 0.7% | Jan 9, 2024 | juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status cod... |
| CVE-2023-50162 | HIGH | 7.2 | 1.0% | Jan 9, 2024 | SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now