2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39137 | HIGH | 7.8 | 0.3% | Aug 30, 2023 | An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. |
| CVE-2023-39136 | MEDIUM | 5.5 | 0.4% | Aug 30, 2023 | An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Servic... |
| CVE-2023-39135 | HIGH | 7.8 | 0.4% | Aug 30, 2023 | An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry. |
| CVE-2023-38970 | MEDIUM | 5.4 | 0.6% | Aug 30, 2023 | Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via... |
| CVE-2023-31714 | CRITICAL | 9.8 | 3.3% | Aug 30, 2023 | Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities. |
| CVE-2023-41039 | HIGH | 7.7 | 0.6% | Aug 30, 2023 | RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality... |
| CVE-2023-40582 | CRITICAL | 9.8 | 1.5% | Aug 30, 2023 | find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input ... |
| CVE-2023-40184 | MEDIUM | 6.5 | 0.7% | Aug 30, 2023 | xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session es... |
| CVE-2023-36811 | MEDIUM | 4.7 | 0.1% | Aug 30, 2023 | borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptog... |
| CVE-2023-4640 | HIGH | 7.5 | 0.3% | Aug 30, 2023 | The controller responsible for setting the logging level does not include any authorization checks to ensure the user is... |
| CVE-2023-4571 | HIGH | 8.6 | 0.2% | Aug 30, 2023 | In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject Am... |
| CVE-2023-40848 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858." |
| CVE-2023-40847 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." I... |
| CVE-2023-40845 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the fun... |
| CVE-2023-40844 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.' |
| CVE-2023-40843 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004." |
| CVE-2023-40842 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler... |
| CVE-2023-40841 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node," |
| CVE-2023-40840 | CRITICAL | 9.8 | 0.6% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat.... |
| CVE-2023-40839 | CRITICAL | 9.8 | 1.0% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In t... |
| CVE-2023-40838 | CRITICAL | 9.8 | 1.1% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability. |
| CVE-2023-40837 | CRITICAL | 9.8 | 0.8% | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In t... |
| CVE-2023-40598 | HIGH | 8.8 | 0.6% | Aug 30, 2023 | In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a leg... |
| CVE-2023-40597 | HIGH | 8.8 | 0.2% | Aug 30, 2023 | In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to... |
| CVE-2023-40596 | HIGH | 8.8 | 0.2% | Aug 30, 2023 | In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now