2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48805 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48804 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48803 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48802 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-34388 | CRITICAL | 9.8 | 0.9% | Nov 30, 2023 | An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthe... |
| CVE-2023-31176 | CRITICAL | 9.8 | 0.9% | Nov 30, 2023 | An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated ... |
| CVE-2023-6360 | CRITICAL | 9.8 | 63.1% | Nov 30, 2023 | The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in th... |
| CVE-2023-6026 | CRITICAL | 9.1 | 0.9% | Nov 30, 2023 | A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability... |
| CVE-2023-49733 | CRITICAL | 9.8 | 1.3% | Nov 30, 2023 | Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: f... |
| CVE-2023-49701 | CRITICAL | 9.8 | 0.5% | Nov 30, 2023 | Memory Corruption in SIM management while USIMPhase2init |
| CVE-2023-47418 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface i... |
| CVE-2023-47463 | CRITICAL | 9.8 | 1.3% | Nov 30, 2023 | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi... |
| CVE-2023-4474 | CRITICAL | 9.8 | 29.7% | Nov 30, 2023 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0... |
| CVE-2023-4473 | CRITICAL | 9.8 | 41.3% | Nov 30, 2023 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fir... |
| CVE-2023-35138 | CRITICAL | 9.8 | 40.0% | Nov 30, 2023 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.... |
| CVE-2023-3741 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execut... |
| CVE-2023-49693 | CRITICAL | 9.8 | 1.2% | Nov 29, 2023 | NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotel... |
| CVE-2023-49091 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ... |
| CVE-2023-49656 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2023-49654 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file ... |
| CVE-2023-6345 | CRITICAL | 9.6 | 19.6% | Nov 29, 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the rend... |
| CVE-2023-45484 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter... |
| CVE-2023-45483 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in th... |
| CVE-2023-45482 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in th... |
| CVE-2023-45481 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now