2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38866 | CRITICAL | 9.8 | 2.1% | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST re... |
| CVE-2023-38864 | CRITICAL | 9.8 | 1.1% | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter... |
| CVE-2023-4344 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup ... |
| CVE-2023-4343 | HIGH | 7.5 | 0.5% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a U... |
| CVE-2023-4342 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security ... |
| CVE-2023-4341 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI |
| CVE-2023-4340 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file |
| CVE-2023-4339 | HIGH | 7.5 | 0.7% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file ... |
| CVE-2023-4338 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide... |
| CVE-2023-4337 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installa... |
| CVE-2023-4336 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua... |
| CVE-2023-4335 | HIGH | 7.5 | 0.5% | Aug 15, 2023 | Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux |
| CVE-2023-4334 | HIGH | 7.5 | 0.5% | Aug 15, 2023 | Broadcom RAID Controller Web server (nginx) is serving private files without any authentication |
| CVE-2023-4333 | MEDIUM | 5.5 | 0.1% | Aug 15, 2023 | Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server |
| CVE-2023-4332 | HIGH | 7.5 | 0.5% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file |
| CVE-2023-4331 | HIGH | 7.5 | 0.3% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and... |
| CVE-2023-4330 | — | — | — | Aug 15, 2023 | Rejected reason: Broadcom were unable to duplicate the attack as described by Intel DCG Team. |
| CVE-2023-4329 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua... |
| CVE-2023-4328 | MEDIUM | 5.5 | 0.1% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are... |
| CVE-2023-4327 | MEDIUM | 5.5 | 0.1% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are ... |
| CVE-2023-4326 | HIGH | 7.5 | 0.3% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SH... |
| CVE-2023-4325 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities |
| CVE-2023-4324 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy h... |
| CVE-2023-4323 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup |
| CVE-2023-38865 | CRITICAL | 9.8 | 2.1% | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST re... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now