LiveActive security incident?Get immediate response
CVE archive

February 2023

Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2128 matching CVEs · Page 16 of 43.

Medium · CVSS 5.9

CVE-2023-0400: The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

Published Feb 1, 2023 · Updated Mar 26, 2025

Medium · CVSS 6.5

CVE-2023-0649: dst-admin sendBroadcast command injection

A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220036.

Published Feb 2, 2023 · Updated Mar 26, 2025

Medium · CVSS 5.4

CVE-2023-0178: Annual Archive < 1.6.0 - Contributor+ Stored XSS

The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 26, 2025

Medium · CVSS 5.4

CVE-2023-0282: YourChannel < 1.2.2 - Subscriber+ Stored XSS

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 26, 2025

Medium · CVSS 5.4

CVE-2023-0154: GamiPress – Vimeo integration < 1.0.9 - Contributor+ Stored XSS

The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.3

CVE-2023-0659: BDCOM 1704-WGL Backup File param.file.tgz information disclosure

A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-220101 was assigned to this vulnerability.

Published Feb 3, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0070: ResponsiveVoice Text To Speech < 1.7.7 - Contributor+ Stored XSS

The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0174: WP VR < 8.2.7 - Contributor+ Stored XSS

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0143: Send PDF for Contact Form 7 < 0.9.9.2 - Contributor+ Stored XSS via Shortcode

The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0082: ExactMetrics < 7.12.1 - Contributor+ Stored XSS

The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0149: WordPrezi < 0.9 - Contributor+ Strored XSS

The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0147: Flexible Captcha <= 4.1 - Contributor+ Stored XSS

The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0171: jQuery T(-) Countdown Widget < 2.3.24 - Contributor+ Stored XSS

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0153: Vimeo Video Autoplay Automute <= 1.0 - Contributor+ Stored XSS

The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

High · CVSS 8.1

CVE-2023-23477: IBM WebSphere Application Server code execution

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

Published Feb 3, 2023 · Updated Mar 25, 2025

Medium · CVSS 6.1

CVE-2023-0599: Rapid7 Metasploit Pro Stored XSS

Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization.  Using this vulnerability, an authenticated attacker can execute arbitrary HTML and script code in the target browser against another Metasploit Pro user using a specially crafted request. Note that in most deployments, all Metasploit Pro users tend to enjoy privileges equivalent to local administrator.

Published Feb 1, 2023 · Updated Mar 25, 2025

High · CVSS 7.5

CVE-2023-23552: BIG-IP Advanced WAF and ASM vulnerability

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Published Feb 1, 2023 · Updated Mar 25, 2025

High · CVSS 8.1

CVE-2023-23849: Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting v...

Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 6.1

CVE-2023-22849: Apache Sling App CMS: XSS in CMS Reference / UI Components

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS >= 1.1.6

Published Feb 4, 2023 · Updated Mar 25, 2025

Medium · CVSS 6.1

CVE-2023-0236: Tutor LMS < 2.0.10 - Reflected Cross-Site Scripting

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0148: Gallery Factory Lite <= 2.0.0 - Contributor+ Stored XSS

The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025

Medium · CVSS 5.4

CVE-2023-0095: Page View Count < 2.6.1 - Contributor+ Stored XSS

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 6, 2023 · Updated Mar 25, 2025