LiveActive security incident?Get immediate response
CVE archive

February 2023

Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2128 matching CVEs · Page 23 of 43.

Medium · CVSS 6.5

CVE-2023-22380: Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.6. This vulnerability was reported via the GitHub Bug Bounty program.

Published Feb 16, 2023 · Updated Mar 19, 2025

Medium · CVSS 6.3

CVE-2023-23558: In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp.

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

Published Feb 16, 2023 · Updated Mar 19, 2025

High · CVSS 7.8

CVE-2023-24996: A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006).

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19818)

Published Feb 14, 2023 · Updated Mar 19, 2025

High · CVSS 7.5

CVE-2023-24580: An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and...

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

Published Feb 15, 2023 · Updated Mar 18, 2025

High · CVSS 7.8

CVE-2023-24992: A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006).

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19814)

Published Feb 14, 2023 · Updated Mar 18, 2025

Medium · CVSS 5.4

CVE-2023-24769: Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerabi...

Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.

Published Feb 17, 2023 · Updated Mar 18, 2025

High · CVSS 8.8

CVE-2023-25266: An issue was discovered in Docmosis Tornado prior to version 2.9.5.

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).

Published Feb 28, 2023 · Updated Mar 18, 2025