2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40900CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNe...
CVE-2023-40899CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and par...
CVE-2023-40898CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/S...
CVE-2023-40897CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetPar...
CVE-2023-40896CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /...
CVE-2023-40895CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVi...
CVE-2023-40894CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetSt...
CVE-2023-40893CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/Power...
CVE-2023-40892CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and sc...
CVE-2023-40891CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform...
CVE-2023-39834CRITICAL9.8PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CVE-2023-40710HIGH7.5An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests...
CVE-2023-40709HIGH7.5An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-...
CVE-2023-40708MEDIUM5.3The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an...
CVE-2023-40707HIGH7.5There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version ...
CVE-2023-40706CRITICAL9.8There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This co...
CVE-2023-34973MEDIUM5.3An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit...
CVE-2023-34972MEDIUM6.5A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If e...
CVE-2023-34971HIGH8.8An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vu...
CVE-2023-40877MEDIUM5.4DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freeli...
CVE-2023-40876MEDIUM5.4DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freeli...
CVE-2023-40875MEDIUM5.4DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /de...
CVE-2023-40874MEDIUM5.4DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /de...
CVE-2023-40371MEDIUM5.5IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of t...
CVE-2023-34040HIGH7.8In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector e...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now