CVE-2023-23463: Sunell DVR – Insufficiently Protected Credentials
Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.
Published Feb 15, 2023 · Updated Mar 19, 2025
Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 2128 matching CVEs · Page 23 of 43.
Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.
Published Feb 15, 2023 · Updated Mar 19, 2025
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
Published Feb 15, 2023 · Updated Mar 19, 2025
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
Published Feb 15, 2023 · Updated Mar 19, 2025
Media CP Media Control Panel latest version. Insufficiently protected credential change.
Published Feb 15, 2023 · Updated Mar 19, 2025
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
Published Feb 15, 2023 · Updated Mar 19, 2025
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published Feb 15, 2024 · Updated Mar 19, 2025
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published Feb 15, 2023 · Updated Mar 19, 2025
PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrator privileges with standard user privileges.
Published Feb 15, 2023 · Updated Mar 19, 2025
AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.
Published Feb 15, 2023 · Updated Mar 19, 2025
AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.
Published Feb 15, 2023 · Updated Mar 19, 2025
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
Published Feb 15, 2023 · Updated Mar 19, 2025
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.6. This vulnerability was reported via the GitHub Bug Bounty program.
Published Feb 16, 2023 · Updated Mar 19, 2025
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
Published Feb 16, 2023 · Updated Mar 19, 2025
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published Feb 14, 2023 · Updated Mar 19, 2025
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19818)
Published Feb 14, 2023 · Updated Mar 19, 2025
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
Published Feb 14, 2024 · Updated Mar 19, 2025
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
Published Feb 16, 2023 · Updated Mar 19, 2025
Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.
Published Feb 18, 2024 · Updated Mar 18, 2025
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
Published Feb 17, 2023 · Updated Mar 18, 2025
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character is missed, will return null pointer.
Published Feb 13, 2025 · Updated Mar 18, 2025
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published Feb 15, 2023 · Updated Mar 18, 2025
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published Feb 15, 2023 · Updated Mar 18, 2025
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.
Published Feb 15, 2023 · Updated Mar 18, 2025
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
Published Feb 16, 2023 · Updated Mar 18, 2025
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
Published Feb 16, 2023 · Updated Mar 18, 2025
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
Published Feb 16, 2023 · Updated Mar 18, 2025
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
Published Feb 16, 2023 · Updated Mar 18, 2025
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.
Published Feb 13, 2025 · Updated Mar 18, 2025
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19814)
Published Feb 14, 2023 · Updated Mar 18, 2025
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
Published Feb 17, 2023 · Updated Mar 18, 2025
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
Published Feb 17, 2023 · Updated Mar 18, 2025
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
Published Feb 17, 2023 · Updated Mar 18, 2025
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
Published Feb 17, 2023 · Updated Mar 18, 2025
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
Published Feb 17, 2023 · Updated Mar 18, 2025
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof “UserData” with desirable file path and access it though backup on USB.
Published Feb 13, 2025 · Updated Mar 18, 2025
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.
Published Feb 13, 2025 · Updated Mar 18, 2025
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Published Feb 17, 2023 · Updated Mar 18, 2025
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
Published Feb 17, 2023 · Updated Mar 18, 2025
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.
Published Feb 17, 2023 · Updated Mar 18, 2025
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
Published Feb 17, 2023 · Updated Mar 18, 2025
Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
Published Feb 17, 2023 · Updated Mar 18, 2025
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
Published Feb 17, 2023 · Updated Mar 18, 2025
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function.
Published Feb 17, 2023 · Updated Mar 18, 2025
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
Published Feb 17, 2023 · Updated Mar 18, 2025
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.
Published Feb 28, 2023 · Updated Mar 18, 2025
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.
Published Feb 17, 2023 · Updated Mar 18, 2025
An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php.
Published Feb 28, 2023 · Updated Mar 18, 2025
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.
Published Feb 15, 2023 · Updated Mar 18, 2025
An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).
Published Feb 28, 2023 · Updated Mar 18, 2025
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.
Published Feb 15, 2023 · Updated Mar 18, 2025