2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-40896CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /...
CVE-2023-40895CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVi...
CVE-2023-40894CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetSt...
CVE-2023-40893CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/Power...
CVE-2023-40892CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and sc...
CVE-2023-40891CRITICAL9.8Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform...
CVE-2023-39834CRITICAL9.8PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CVE-2023-40706CRITICAL9.8There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This co...
CVE-2023-4041CRITICAL9.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without In...
CVE-2023-4404CRITICAL9.8The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu...
CVE-2023-38734CRITICAL9.8 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege a...
CVE-2023-36281CRITICAL9.8An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This ...
CVE-2023-4373CRITICAL9.8 Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager v...
CVE-2023-39660CRITICAL9.8An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a craft...
CVE-2023-38961CRITICAL9.8Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary c...
CVE-2023-38035CRITICAL9.8A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an ...
CVE-2023-32002CRITICAL9.8The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition fo...
CVE-2023-31447CRITICAL9.8user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers t...
CVE-2023-39939CRITICAL9.1SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2....
CVE-2023-4450CRITICAL9.8A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulner...
CVE-2023-39751CRITICAL9.8TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.
CVE-2023-39750CRITICAL9.8D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vul...
CVE-2023-39749CRITICAL9.8D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is...
CVE-2023-39747CRITICAL9.8TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSe...
CVE-2023-4448CRITICAL9.8A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown proces...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now