2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40900 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNe... |
| CVE-2023-40899 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and par... |
| CVE-2023-40898 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/S... |
| CVE-2023-40897 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetPar... |
| CVE-2023-40896 | CRITICAL | 9.8 | 1.0% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /... |
| CVE-2023-40895 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVi... |
| CVE-2023-40894 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetSt... |
| CVE-2023-40893 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/Power... |
| CVE-2023-40892 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and sc... |
| CVE-2023-40891 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform... |
| CVE-2023-39834 | CRITICAL | 9.8 | 1.8% | Aug 24, 2023 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. |
| CVE-2023-40710 | HIGH | 7.5 | 0.4% | Aug 24, 2023 | An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests... |
| CVE-2023-40709 | HIGH | 7.5 | 0.4% | Aug 24, 2023 | An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-... |
| CVE-2023-40708 | MEDIUM | 5.3 | 0.4% | Aug 24, 2023 | The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an... |
| CVE-2023-40707 | HIGH | 7.5 | 0.5% | Aug 24, 2023 | There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version ... |
| CVE-2023-40706 | CRITICAL | 9.8 | 0.5% | Aug 24, 2023 | There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This co... |
| CVE-2023-34973 | MEDIUM | 5.3 | 0.4% | Aug 24, 2023 | An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit... |
| CVE-2023-34972 | MEDIUM | 6.5 | 0.2% | Aug 24, 2023 | A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If e... |
| CVE-2023-34971 | HIGH | 8.8 | 0.1% | Aug 24, 2023 | An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vu... |
| CVE-2023-40877 | MEDIUM | 5.4 | 0.4% | Aug 24, 2023 | DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freeli... |
| CVE-2023-40876 | MEDIUM | 5.4 | 0.4% | Aug 24, 2023 | DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freeli... |
| CVE-2023-40875 | MEDIUM | 5.4 | 0.4% | Aug 24, 2023 | DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /de... |
| CVE-2023-40874 | MEDIUM | 5.4 | 0.4% | Aug 24, 2023 | DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /de... |
| CVE-2023-40371 | MEDIUM | 5.5 | 0.1% | Aug 24, 2023 | IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of t... |
| CVE-2023-34040 | HIGH | 7.8 | 2.2% | Aug 24, 2023 | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector e... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now