2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49429CRITICAL9.8Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature th...
CVE-2023-49437CRITICAL9.8Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gof...
CVE-2023-49428CRITICAL9.8Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofo...
CVE-2023-49426CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
CVE-2023-49425CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterC...
CVE-2023-39171HIGH7.2SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
CVE-2023-39170Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it's a duplicate of C...
CVE-2023-39169CRITICAL9.8The affected devices use publicly available default credentials with administrative privileges.
CVE-2023-49424CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg...
CVE-2023-46974MEDIUM5.4Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitra...
CVE-2023-39172CRITICAL9.1The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture an...
CVE-2023-39168Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it's a duplicate of C...
CVE-2023-39167HIGH7.5In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensi...
CVE-2023-49958HIGH7.5An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. ...
CVE-2023-49957HIGH7.5An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I...
CVE-2023-49956HIGH7.5An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A...
CVE-2023-49955HIGH7.5An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I...
CVE-2023-47548MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Do...
CVE-2023-45762MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.T...
CVE-2023-48325MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin ...
CVE-2023-47779MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Con...
CVE-2023-35909MEDIUM5.3Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Buil...
CVE-2023-35039CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset wit...
CVE-2023-49746MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This...
CVE-2023-46641MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Me...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now