2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40302CRITICAL9.1NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability
CVE-2023-40301CRITICAL9.8NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.
CVE-2023-40300CRITICAL9.8NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
CVE-2023-39909HIGH8.8Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access t...
CVE-2023-33413HIGH8.8The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller ...
CVE-2023-33412HIGH8.8The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implemen...
CVE-2023-33411HIGH7.5A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementatio...
CVE-2023-50002CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
CVE-2023-50001CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
CVE-2023-50000CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
CVE-2023-49999CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPa...
CVE-2023-49410CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status...
CVE-2023-49403CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
CVE-2023-49402CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
CVE-2023-6588MEDIUM6.5 Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Wo...
CVE-2023-49967HIGH7.5Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xml...
CVE-2023-49493MEDIUM6.1DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at ...
CVE-2023-49492MEDIUM6.1DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parame...
CVE-2023-49436CRITICAL9.8Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gofo...
CVE-2023-49435CRITICAL9.8Tenda AX9 V22.03.01.46 is vulnerable to command injection.
CVE-2023-49434CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNe...
CVE-2023-49433CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVi...
CVE-2023-49432CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform...
CVE-2023-49431CRITICAL9.8Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofor...
CVE-2023-49430CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetSt...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now