2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5546MEDIUM5.4ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
CVE-2023-5545MEDIUM5.3H5P metadata automatically populated the author with the user's username, which could be sensitive information.
CVE-2023-5544MEDIUM5.4Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR ris...
CVE-2023-5542MEDIUM4.3Students in "Only see own membership" groups could see other students in the group, which should be hidden.
CVE-2023-5541MEDIUM6.1The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
CVE-2023-5540HIGH8.8A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and ma...
CVE-2023-5539HIGH8.8A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and m...
CVE-2023-39198MEDIUM6.4A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the q...
CVE-2023-34177HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kenth Hagström WP-Cache.Com plugin <= 1.1.1 versions.
CVE-2023-34171HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alex Raven WP Report Post plugin <= 2.1.2 versions.
CVE-2023-34169HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 vers...
CVE-2023-34033HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Malinky Ajax Pagination and Infinite Scroll plugin <= 2.0.1 versions.
CVE-2023-6054CRITICAL9.8A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part ...
CVE-2023-6053CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.9. Affected by this issue i...
CVE-2023-47238HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3...
CVE-2023-47237HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versi...
CVE-2023-34371HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.
CVE-2023-34182HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.
CVE-2023-34181HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP-Cirrus plugin <= 0.6.11 versions.
CVE-2023-34178HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions.
CVE-2023-46614HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mat Bao Corp WP Helper Premium plugin <= 4.5.1 versions.
CVE-2023-34386HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
CVE-2023-34002HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.
CVE-2023-31087HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.
CVE-2023-25975HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Frédéric Sheedy Etsy Shop plugin <= 3.0.3 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now