2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34570MEDIUM6.7Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/...
CVE-2023-34569MEDIUM6.7Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/Set...
CVE-2023-34568MEDIUM6.7Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/Pow...
CVE-2023-34567MEDIUM6.7Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/Set...
CVE-2023-34566CRITICAL9.8Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/sav...
CVE-2023-3163HIGH7.5A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the functio...
CVE-2023-33443CRITICAL9.8Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attacke...
CVE-2023-33657HIGH7.5A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_m...
CVE-2023-33660HIGH7.5A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function...
CVE-2023-33658HIGH7.5A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function...
CVE-2023-34969MEDIUM6.5D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the...
CVE-2023-2986CRITICAL9.8The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a...
CVE-2023-23482CRITICAL9.6IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action ...
CVE-2023-23481MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerabi...
CVE-2023-23480MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2023-33847LOW3.1 IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the...
CVE-2023-33846MEDIUM5.4IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to ...
CVE-2023-34239CRITICAL9.1Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f...
CVE-2023-34238MEDIUM5.3Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 conta...
CVE-2023-33849LOW3.7IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit se...
CVE-2023-31200HIGH8 PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-sit...
CVE-2023-2904HIGH7.3The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within we...
CVE-2023-29502MEDIUM4.3 Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.jso...
CVE-2023-29168HIGH7.5The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication....
CVE-2023-29152HIGH8.1 By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vufo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now