2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45806MEDIUM5.4Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version...
CVE-2023-23367HIGH7.2An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-31078HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.4.1 versions.
CVE-2023-31077HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.
CVE-2023-30478HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
CVE-2023-29440HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions.
CVE-2023-29428HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for Wo...
CVE-2023-29426HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Robert Schulz (sprd.Net AG) Spreadshop plugin <= 1.6.5 versions.
CVE-2023-47164MEDIUM6.1Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute a...
CVE-2023-6073MEDIUM6.3Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of ...
CVE-2023-47800CRITICAL9.8Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service...
CVE-2023-47246CRITICAL9.8In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f...
CVE-2023-39796CRITICAL9.8SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute...
CVE-2023-45167MEDIUM5.5IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial...
CVE-2023-6069HIGH8.8Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
CVE-2023-46729MEDIUM6.1sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sendin...
CVE-2023-36024HIGH7.1Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-36014HIGH7.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2023-32502HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0....
CVE-2023-32501HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 vers...
CVE-2023-32500HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions.
CVE-2023-32125HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions.
CVE-2023-32093HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Criss Swaim TPG Redirect plugin <= 1.0.7 versions.
CVE-2023-32092HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration...
CVE-2023-31235HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 v...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now