LiveActive security incident?Get immediate response
CVE archive

February 2023

Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2128 matching CVEs · Page 20 of 43.

High · CVSS 7.8

CVE-2023-22350: Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because...

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22353: Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because...

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22360: Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack...

Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

Critical · CVSS 9.8

CVE-2023-20946: In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a conf...

In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-244423101

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20945: In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to...

In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-246932269

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20944: In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe dese...

In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-244154558

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20943: In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files...

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240267890

Published Feb 28, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.5

CVE-2023-24619: Redpanda before 22.3.12 discloses cleartext AWS credentials.

Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12, 22.2.10, and 22.1.12.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0169: Zoho Forms < 3.0.1 - Contributor+ Stored XSS

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 8.8

CVE-2023-0260: WP Review Slider < 12.2 - Subscriber+ SQLi

The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20940: In the Android operating system, there is a possible way to replace a boot partition due to improperly used...

In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256237041

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20939: In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to imp...

In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-243362981

Published Feb 28, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0362: Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20937: In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use af...

In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257443051References: Upstream kernel

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20934: In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone priv...

In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-258672042

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-20933: In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free.

In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-245860753

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 8.8

CVE-2023-0220: Pinpoint Booking System < 2.9.9.2.9 - Subscriber+ SQLi

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0373: Lightweight Accordion < 1.5.15 - Contributor+ Stored XSS

The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0333: TemplatesNext ToolKit < 3.2.9 - Contributor+ Stored XSS

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published Feb 13, 2023 · Updated Mar 21, 2025

Low · CVSS 3.3

CVE-2023-20932: In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to othe...

In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018

Published Feb 28, 2023 · Updated Mar 21, 2025

High · CVSS 8.8

CVE-2023-0261: WP TripAdvisor Review Slider < 10.8 - Subscriber+ SQLi

The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0275: Easy Accept Payments for PayPal < 4.9.10 - Contributor+ Stored XSS

The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 8.8

CVE-2023-0259: WP Google Review Slider < 11.8 - Subscriber+ SQLi

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0166: PickPlugins Product Slider for WooCommerce < 1.13.42 - Contributor+ Stored XSS

The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 8.8

CVE-2023-0080: Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0151: uTubeVideo Gallery < 2.0.8 - Contributor+ Stored XSS

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.8

CVE-2023-22349: Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because...

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0379: Spotlight Social Feeds < 1.4.3 - Contributor+ Stored XSS

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0270: YaMaps for WordPress Plugin < 0.6.26 - Contributor+ Stored XSS

The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-0060: Responsive Gallery Grid < 2.3.9 - Contributor+ Stored XSS

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Published Feb 13, 2023 · Updated Mar 21, 2025

High · CVSS 7.5

CVE-2023-22362: SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obta...

SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan SUSHIRO Ver.2.0.1

Published Feb 13, 2023 · Updated Mar 21, 2025

Medium · CVSS 5.4

CVE-2023-23851: SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization...

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

Published Feb 14, 2023 · Updated Mar 21, 2025

Medium · CVSS 6.1

CVE-2023-24521: Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731...

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.

Published Feb 14, 2023 · Updated Mar 21, 2025