2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31093HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions.
CVE-2023-31088HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Faraz Quazi Floating Action Button plugin <= 1.2.1 versions.
CVE-2023-31086HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and tra...
CVE-2023-5543LOW3.3When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the...
CVE-2023-32592HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <= 1....
CVE-2023-32587HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions.
CVE-2023-32579HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 version...
CVE-2023-32512HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimi...
CVE-2023-29975HIGH7.2An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification...
CVE-2023-5954HIGH7.5HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumpt...
CVE-2023-4379HIGH7.5An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3....
CVE-2023-34031HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.
CVE-2023-34025HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Hide Login plugin <= 2.1.6 versions.
CVE-2023-34024HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Guillemant David WP Full Auto Tags Manager plugin <= 2.2 versions.
CVE-2023-32794HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Add-Ons plugin <= 6.1.3 versions.
CVE-2023-32745HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions.
CVE-2023-32744HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Recommendations plugin <= 2.3.0 versions.
CVE-2023-32739HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 v...
CVE-2023-32602HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LOKALYZE CALL ME NOW plugin <= 3.0 versions.
CVE-2023-32594HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Benedict B., Maciej Gryniuk Hyphenator plugin <= 5.1.5 versions.
CVE-2023-5551LOW3.3Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other gr...
CVE-2023-5550CRITICAL9.8In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who a...
CVE-2023-5549MEDIUM5.3Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par...
CVE-2023-5548MEDIUM5.3Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
CVE-2023-5547MEDIUM6.1The course upload preview contained an XSS risk for users uploading unsafe data.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now