Medium · CVSS 4
Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.5
Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.5
Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.5
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.2
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.7
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.
Published Feb 9, 2023 · Updated Mar 24, 2025
Low · CVSS 2.3
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.7
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.5
WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.3
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.1
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.3
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.3
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
Published Feb 9, 2023 · Updated Mar 24, 2025
Low · CVSS 3.3
Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.2
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.8
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.4
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
Published Feb 9, 2023 · Updated Mar 24, 2025
Low · CVSS 3.3
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
Published Feb 9, 2023 · Updated Mar 24, 2025
Low · CVSS 2.1
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 8.5
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.2
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.2
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.2
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.8
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.4
Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.3
An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.
Published Feb 9, 2023 · Updated Mar 24, 2025
High · CVSS 7.8
Dell Alienware Command Center versions 5.5.37.0 and prior contain an Improper Input validation vulnerability. A local authenticated malicious user could potentially send malicious input to a named pipe in order to elevate privileges on the system.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.7
Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.5
Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 7.2
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py.
This issue affects Yugabyte DB: Lesser then 2.2.0.0
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.7
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path traversal characters.
This vulnerability is associated with program files PlatformReplicationManager.Java.
This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.8
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel Manipulation, Authentication Abuse.This issue affects Yugabyte Managed: from 2.0.0.0 through 2.13.0.0
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.3
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 6.5
A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability.
Published Feb 9, 2023 · Updated Mar 24, 2025
Critical · CVSS 9.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.
Published Feb 10, 2023 · Updated Mar 24, 2025
High · CVSS 8.8
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.3
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 5.4
ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.
Published Feb 9, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.8
A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page title parameter.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.8
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.8
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
Published Feb 10, 2023 · Updated Mar 24, 2025
Medium · CVSS 4.8
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Client Name parameter.
Published Feb 10, 2023 · Updated Mar 24, 2025