2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49403 | CRITICAL | 9.8 | 2.2% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools. |
| CVE-2023-49402 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. |
| CVE-2023-49436 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gofo... |
| CVE-2023-49435 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. |
| CVE-2023-49434 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNe... |
| CVE-2023-49433 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVi... |
| CVE-2023-49432 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform... |
| CVE-2023-49431 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofor... |
| CVE-2023-49430 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetSt... |
| CVE-2023-49429 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature th... |
| CVE-2023-49437 | CRITICAL | 9.8 | 2.4% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gof... |
| CVE-2023-49428 | CRITICAL | 9.8 | 2.5% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofo... |
| CVE-2023-49426 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. |
| CVE-2023-49425 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterC... |
| CVE-2023-39169 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | The affected devices use publicly available default credentials with administrative privileges. |
| CVE-2023-49424 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg... |
| CVE-2023-39172 | CRITICAL | 9.1 | 0.6% | Dec 7, 2023 | The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture an... |
| CVE-2023-35039 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset wit... |
| CVE-2023-50164 | CRITICAL | 9.8 | 80.8% | Dec 7, 2023 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to up... |
| CVE-2023-48860 | CRITICAL | 9.8 | 1.4% | Dec 7, 2023 | TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attac... |
| CVE-2023-48823 | CRITICAL | 9.8 | 1.1% | Dec 7, 2023 | A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker t... |
| CVE-2023-41913 | CRITICAL | 9.8 | 2.3% | Dec 7, 2023 | strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value ... |
| CVE-2023-46353 | CRITICAL | 9.8 | 0.8% | Dec 6, 2023 | In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL inj... |
| CVE-2023-36655 | CRITICAL | 9.8 | 1.0% | Dec 6, 2023 | The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a r... |
| CVE-2023-6458 | CRITICAL | 9.8 | 0.6% | Dec 6, 2023 | Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now