2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49429 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature th... |
| CVE-2023-49437 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gof... |
| CVE-2023-49428 | CRITICAL | 9.8 | 2.5% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofo... |
| CVE-2023-49426 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. |
| CVE-2023-49425 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterC... |
| CVE-2023-39171 | HIGH | 7.2 | 1.1% | Dec 7, 2023 | SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials. |
| CVE-2023-39170 | — | — | — | Dec 7, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it's a duplicate of C... |
| CVE-2023-39169 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | The affected devices use publicly available default credentials with administrative privileges. |
| CVE-2023-49424 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg... |
| CVE-2023-46974 | MEDIUM | 5.4 | 0.7% | Dec 7, 2023 | Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitra... |
| CVE-2023-39172 | CRITICAL | 9.1 | 0.6% | Dec 7, 2023 | The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture an... |
| CVE-2023-39168 | — | — | — | Dec 7, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it's a duplicate of C... |
| CVE-2023-39167 | HIGH | 7.5 | 1.0% | Dec 7, 2023 | In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensi... |
| CVE-2023-49958 | HIGH | 7.5 | 0.6% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. ... |
| CVE-2023-49957 | HIGH | 7.5 | 0.5% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I... |
| CVE-2023-49956 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A... |
| CVE-2023-49955 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I... |
| CVE-2023-47548 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Do... |
| CVE-2023-45762 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.T... |
| CVE-2023-48325 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin ... |
| CVE-2023-47779 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Con... |
| CVE-2023-35909 | MEDIUM | 5.3 | 0.6% | Dec 7, 2023 | Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Buil... |
| CVE-2023-35039 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset wit... |
| CVE-2023-49746 | MEDIUM | 4.3 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This... |
| CVE-2023-46641 | MEDIUM | 5.4 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Me... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now