2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2781CRITICAL9.8The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate...
CVE-2023-3044LOW3.3An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero ...
CVE-2023-2816MEDIUM6.5Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via serv...
CVE-2023-1297HIGH7.5Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of th...
CVE-2023-33763MEDIUM6.1eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnera...
CVE-2023-33762CRITICAL9.8eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity...
CVE-2023-33761MEDIUM6.1eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnera...
CVE-2023-33675CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_li...
CVE-2023-33673CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal...
CVE-2023-33672HIGH7.5Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...
CVE-2023-33671CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentContro...
CVE-2023-33670CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.
CVE-2023-33669CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct...
CVE-2023-3073MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.
CVE-2023-3075MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3074MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3071MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3070MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3069CRITICAL9.8Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-32215HIGH8.8Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCre...
CVE-2023-32213HIGH8.8When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113...
CVE-2023-32212MEDIUM4.3An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < ...
CVE-2023-32211MEDIUM6.5A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR...
CVE-2023-32207HIGH8.8A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permiss...
CVE-2023-32206MEDIUM6.5An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Fire...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now