High · CVSS 7.8
Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.9
Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.
Published Feb 13, 2023 · Updated Mar 21, 2025
Critical · CVSS 9.8
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
Published Feb 13, 2023 · Updated Mar 21, 2025
Critical · CVSS 9.8
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-244423101
Published Feb 28, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.1
SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-246932269
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-244154558
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240267890
Published Feb 28, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.5
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12, 22.2.10, and 22.1.12.
Published Feb 13, 2023 · Updated Mar 21, 2025
Critical · CVSS 9.8
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.5
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.1
Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256237041
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-243362981
Published Feb 28, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257443051References: Upstream kernel
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-258672042
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-245860753
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 13, 2023 · Updated Mar 21, 2025
Low · CVSS 3.3
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018
Published Feb 28, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.1
bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 4.7
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 4.7
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.8
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 8.8
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.3
Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.5
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan SUSHIRO Ver.2.0.1
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.1
Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Published Feb 13, 2023 · Updated Mar 21, 2025
High · CVSS 7.8
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Published Feb 13, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.5
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources.
Published Feb 14, 2023 · Updated Mar 21, 2025
Medium · CVSS 5.4
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.
Published Feb 14, 2023 · Updated Mar 21, 2025
Medium · CVSS 6.1
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
Published Feb 14, 2023 · Updated Mar 21, 2025