2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-49403CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
CVE-2023-49402CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
CVE-2023-49436CRITICAL9.8Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gofo...
CVE-2023-49435CRITICAL9.8Tenda AX9 V22.03.01.46 is vulnerable to command injection.
CVE-2023-49434CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNe...
CVE-2023-49433CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVi...
CVE-2023-49432CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform...
CVE-2023-49431CRITICAL9.8Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofor...
CVE-2023-49430CRITICAL9.8Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetSt...
CVE-2023-49429CRITICAL9.8Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature th...
CVE-2023-49437CRITICAL9.8Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /gof...
CVE-2023-49428CRITICAL9.8Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /gofo...
CVE-2023-49426CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
CVE-2023-49425CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterC...
CVE-2023-39169CRITICAL9.8The affected devices use publicly available default credentials with administrative privileges.
CVE-2023-49424CRITICAL9.8Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg...
CVE-2023-39172CRITICAL9.1The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture an...
CVE-2023-35039CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset wit...
CVE-2023-50164CRITICAL9.8An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to up...
CVE-2023-48860CRITICAL9.8TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attac...
CVE-2023-48823CRITICAL9.8A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker t...
CVE-2023-41913CRITICAL9.8strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value ...
CVE-2023-46353CRITICAL9.8In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL inj...
CVE-2023-36655CRITICAL9.8The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a r...
CVE-2023-6458CRITICAL9.8Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now