2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6617 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Af... |
| CVE-2023-6612 | CRITICAL | 9.8 | 30.7% | Dec 8, 2023 | A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects t... |
| CVE-2023-48423 | CRITICAL | 9.8 | 0.5% | Dec 8, 2023 | In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2023-49443 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerabil... |
| CVE-2023-49007 | CRITICAL | 9.8 | 9.0% | Dec 8, 2023 | In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. |
| CVE-2023-48929 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' p... |
| CVE-2023-43742 | CRITICAL | 9.8 | 0.9% | Dec 8, 2023 | An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17... |
| CVE-2023-5008 | CRITICAL | 9.8 | 0.9% | Dec 8, 2023 | Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter... |
| CVE-2023-6581 | CRITICAL | 9.8 | 4.0% | Dec 7, 2023 | A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects ... |
| CVE-2023-6579 | CRITICAL | 9.8 | 23.8% | Dec 7, 2023 | A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknow... |
| CVE-2023-35618 | CRITICAL | 9.6 | 2.9% | Dec 7, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-49411 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. |
| CVE-2023-49409 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet. |
| CVE-2023-49408 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. |
| CVE-2023-49406 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet... |
| CVE-2023-49405 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. |
| CVE-2023-49404 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. |
| CVE-2023-40302 | CRITICAL | 9.1 | 0.8% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability |
| CVE-2023-40301 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. |
| CVE-2023-40300 | CRITICAL | 9.8 | 0.7% | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. |
| CVE-2023-50002 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode. |
| CVE-2023-50001 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline. |
| CVE-2023-50000 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode. |
| CVE-2023-49999 | CRITICAL | 9.8 | 2.2% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPa... |
| CVE-2023-49410 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now