2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40896 | CRITICAL | 9.8 | 1.0% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /... |
| CVE-2023-40895 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVi... |
| CVE-2023-40894 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetSt... |
| CVE-2023-40893 | CRITICAL | 9.8 | 0.8% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/Power... |
| CVE-2023-40892 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and sc... |
| CVE-2023-40891 | CRITICAL | 9.8 | 0.7% | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform... |
| CVE-2023-39834 | CRITICAL | 9.8 | 1.8% | Aug 24, 2023 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. |
| CVE-2023-40706 | CRITICAL | 9.8 | 0.5% | Aug 24, 2023 | There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This co... |
| CVE-2023-4041 | CRITICAL | 9.8 | 0.3% | Aug 23, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without In... |
| CVE-2023-4404 | CRITICAL | 9.8 | 0.8% | Aug 23, 2023 | The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu... |
| CVE-2023-38734 | CRITICAL | 9.8 | 0.6% | Aug 22, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege a... |
| CVE-2023-36281 | CRITICAL | 9.8 | 2.8% | Aug 22, 2023 | An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This ... |
| CVE-2023-4373 | CRITICAL | 9.8 | 0.7% | Aug 21, 2023 | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager v... |
| CVE-2023-39660 | CRITICAL | 9.8 | 1.3% | Aug 21, 2023 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a craft... |
| CVE-2023-38961 | CRITICAL | 9.8 | 1.2% | Aug 21, 2023 | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary c... |
| CVE-2023-38035 | CRITICAL | 9.8 | 99.9% | Aug 21, 2023 | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an ... |
| CVE-2023-32002 | CRITICAL | 9.8 | 1.4% | Aug 21, 2023 | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition fo... |
| CVE-2023-31447 | CRITICAL | 9.8 | 0.9% | Aug 21, 2023 | user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers t... |
| CVE-2023-39939 | CRITICAL | 9.1 | 0.7% | Aug 21, 2023 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.... |
| CVE-2023-4450 | CRITICAL | 9.8 | 11.4% | Aug 21, 2023 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulner... |
| CVE-2023-39751 | CRITICAL | 9.8 | 7.8% | Aug 21, 2023 | TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm. |
| CVE-2023-39750 | CRITICAL | 9.8 | 12.8% | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vul... |
| CVE-2023-39749 | CRITICAL | 9.8 | 1.0% | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is... |
| CVE-2023-39747 | CRITICAL | 9.8 | 7.8% | Aug 21, 2023 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSe... |
| CVE-2023-4448 | CRITICAL | 9.8 | 0.5% | Aug 21, 2023 | A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown proces... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now