2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40302 | CRITICAL | 9.1 | 0.8% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability |
| CVE-2023-40301 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. |
| CVE-2023-40300 | CRITICAL | 9.8 | 0.7% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. |
| CVE-2023-39909 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access t... |
| CVE-2023-33413 | HIGH | 8.8 | 1.0% | Dec 7, 2023 | The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller ... |
| CVE-2023-33412 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implemen... |
| CVE-2023-33411 | HIGH | 7.5 | 1.3% | Dec 7, 2023 | A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementatio... |
| CVE-2023-50002 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode. |
| CVE-2023-50001 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline. |
| CVE-2023-50000 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode. |
| CVE-2023-49999 | CRITICAL | 9.8 | 2.2% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPa... |
| CVE-2023-49410 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status... |
| CVE-2023-49403 | CRITICAL | 9.8 | 2.2% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools. |
| CVE-2023-49402 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. |
| CVE-2023-6588 | MEDIUM | 6.5 | 0.6% | Dec 7, 2023 | Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Wo... |
| CVE-2023-49967 | HIGH | 7.5 | 0.8% | Dec 7, 2023 | Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xml... |
| CVE-2023-49493 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at ... |
| CVE-2023-49492 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parame... |
| CVE-2023-49436 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gofo... |
| CVE-2023-49435 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. |
| CVE-2023-49434 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNe... |
| CVE-2023-49433 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVi... |
| CVE-2023-49432 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform... |
| CVE-2023-49431 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofor... |
| CVE-2023-49430 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetSt... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now