LiveActive security incident?Get immediate response
CVE archive

February 2023

Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2128 matching CVEs · Page 19 of 43.

High · CVSS 8.1

CVE-2023-0776: Remote Code Execution in Baicells QRTB Platform

Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce.

Published Feb 10, 2023 · Updated Mar 24, 2025

High · CVSS 7.5

CVE-2023-22832: Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor.

Published Feb 10, 2023 · Updated Mar 24, 2025

High · CVSS 8.3

CVE-2023-0782: Tenda AC23 httpd formGetSysToolDDNS out-of-bounds write

A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640.

Published Feb 11, 2023 · Updated Mar 24, 2025

Medium · CVSS 5.4

CVE-2023-27294: Improper neutralization of input during web page generation allows an authenticated attacker with access to...

Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then be executed in other users' browsers if they browse to that event. This could result in stealing session tokens from users with higher permission levels or forcing users to make actions without their knowledge.

Published Feb 28, 2023 · Updated Mar 21, 2025

Medium · CVSS 6.1

CVE-2023-27293: Improper neutralization of input during web page generation allows an unauthenticated attacker to submit ma...

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.7

CVE-2023-0262: WP Airbnb Review Slider < 3.3 - Subscriber+ SQLi

The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 6.8

CVE-2023-0075: Amazon JS <= 0.10 - Contributor+ Stored XSS

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

Unknown · CVSS Not scored

CVE-2023-0263: WP Yelp Review Slider < 7.1 - Subscriber+ SQLi

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.7

CVE-2023-0098: Simple URLs < 115 - Subscriber+ SQLi

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 6.8

CVE-2023-0061: Judge.me Product Reviews for WooCommerce < 1.3.21 - Contributor+ Stored XSS

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22345: Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to...

Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22346: Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because...

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing template information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22347: Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because...

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing file structure information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025