2023 CVE Vulnerabilities

31,402 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35193HIGH8.8An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v...
CVE-2023-35056CRITICAL9.8A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially cr...
CVE-2023-35055CRITICAL9.8A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially cr...
CVE-2023-34426CRITICAL9.8A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_2022110...
CVE-2023-34365CRITICAL9.8A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20...
CVE-2023-34356HIGH8.8An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in ...
CVE-2023-34354MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 ...
CVE-2023-34346CRITICAL9.8A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108...
CVE-2023-32645CRITICAL9.8A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A ...
CVE-2023-32632CRITICAL9.8A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. ...
CVE-2023-31272CRITICAL9.8A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A spe...
CVE-2023-28381HIGH8.8An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6....
CVE-2023-27380HIGH8.8An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (i...
CVE-2023-24479CRITICAL9.8An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A speci...
CVE-2023-4957MEDIUM4.3A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulne...
CVE-2023-45396MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter...
CVE-2023-44119HIGH7.5Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will aff...
CVE-2023-44118CRITICAL9.1Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect a...
CVE-2023-44116CRITICAL9.8Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this ...
CVE-2023-44114HIGH7.5Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service...
CVE-2023-44108HIGH7.5Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the ...
CVE-2023-44107CRITICAL9.1 Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of th...
CVE-2023-44105CRITICAL9.8Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this...
CVE-2023-37538MEDIUM6.1HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In...
CVE-2023-5521CRITICAL9.8Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now