2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50585CRITICAL9.8Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fun...
CVE-2023-49237CRITICAL9.8An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system fun...
CVE-2023-49236CRITICAL9.8A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command ...
CVE-2023-49235CRITICAL9.8An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information...
CVE-2023-7220CRITICAL9.8A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue i...
CVE-2023-6147MEDIUM6.5Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu...
CVE-2023-6842MEDIUM4.8The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress i...
CVE-2023-6830MEDIUM6.1The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu...
CVE-2023-50932MEDIUM5.4An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, th...
CVE-2023-50931MEDIUM5.4An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the...
CVE-2023-50930HIGH7.1An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the conf...
CVE-2023-7219CRITICAL9.8A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulne...
CVE-2023-6788MEDIUM5.4The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2023-6594MEDIUM4.8The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti...
CVE-2023-51717CRITICAL9.8Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
CVE-2023-49238CRITICAL9.8In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain insta...
CVE-2023-39336HIGH8.8An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker wi...
CVE-2023-36629MEDIUM5.5The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
CVE-2023-27098HIGH7.5TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
CVE-2023-27000MEDIUM6.1Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod...
CVE-2023-26999CRITICAL9.8An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of s...
CVE-2023-26998MEDIUM5.4Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod...
CVE-2023-50643CRITICAL9.8An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode a...
CVE-2023-46906MEDIUM4.9juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status cod...
CVE-2023-50162HIGH7.2SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive in...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now