2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5931 | HIGH | 8.8 | 0.8% | Dec 26, 2023 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded,... |
| CVE-2023-5674 | HIGH | 8.8 | 10.8% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2023-5673 | HIGH | 8.8 | 1.1% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to em... |
| CVE-2023-5672 | MEDIUM | 6.5 | 0.7% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to em... |
| CVE-2023-5645 | HIGH | 8.8 | 0.7% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2023-5644 | HIGH | 7.6 | 0.5% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with t... |
| CVE-2023-5203 | HIGH | 7.5 | 2.2% | Dec 26, 2023 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query ... |
| CVE-2023-52086 | HIGH | 8.1 | 0.7% | Dec 26, 2023 | resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the files... |
| CVE-2023-51102 | CRITICAL | 9.8 | 0.7% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet. |
| CVE-2023-51101 | CRITICAL | 9.8 | 0.7% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo. |
| CVE-2023-51100 | CRITICAL | 9.8 | 1.8% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseI... |
| CVE-2023-51099 | CRITICAL | 9.8 | 1.9% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand . |
| CVE-2023-51098 | CRITICAL | 9.8 | 1.8% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseI... |
| CVE-2023-51097 | CRITICAL | 9.8 | 0.8% | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing. |
| CVE-2023-51094 | CRITICAL | 9.8 | 1.1% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet. |
| CVE-2023-51093 | CRITICAL | 9.8 | 0.8% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo. |
| CVE-2023-51092 | CRITICAL | 9.8 | 12.9% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade. |
| CVE-2023-51091 | CRITICAL | 9.8 | 8.5% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler. |
| CVE-2023-51090 | CRITICAL | 9.8 | 0.7% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig. |
| CVE-2023-45251 | — | — | — | Dec 26, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2023-43851 | — | — | — | Dec 26, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2023-51095 | CRITICAL | 9.8 | 0.8% | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy. |
| CVE-2023-51467 | CRITICAL | 9.8 | 96.0% | Dec 26, 2023 | The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary ... |
| CVE-2023-51107 | HIGH | 7.5 | 0.7% | Dec 26, 2023 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_colo... |
| CVE-2023-51106 | HIGH | 7.5 | 0.7% | Dec 26, 2023 | A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_ima... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now