2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38866CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST re...
CVE-2023-38864CRITICAL9.8An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter...
CVE-2023-4344CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup ...
CVE-2023-4343HIGH7.5Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a U...
CVE-2023-4342CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security ...
CVE-2023-4341CRITICAL9.8Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
CVE-2023-4340CRITICAL9.8Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
CVE-2023-4339HIGH7.5Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file ...
CVE-2023-4338CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide...
CVE-2023-4337CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installa...
CVE-2023-4336CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua...
CVE-2023-4335HIGH7.5Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
CVE-2023-4334HIGH7.5Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
CVE-2023-4333MEDIUM5.5Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
CVE-2023-4332HIGH7.5Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
CVE-2023-4331HIGH7.5Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and...
CVE-2023-4330Rejected reason: Broadcom were unable to duplicate the attack as described by Intel DCG Team.
CVE-2023-4329CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua...
CVE-2023-4328MEDIUM5.5Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are...
CVE-2023-4327MEDIUM5.5Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are ...
CVE-2023-4326HIGH7.5Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SH...
CVE-2023-4325CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
CVE-2023-4324CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy h...
CVE-2023-4323CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
CVE-2023-38865CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST re...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now