LiveActive security incident?Get immediate response
CVE archive

February 2023

Browse CVE records published in February 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2128 matching CVEs · Page 7 of 43.

High · CVSS 7.2

CVE-2023-47618: A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link...

A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-47617: A post authentication command injection vulnerability exists when configuring the web group member of Tp-Li...

A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-47209: A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link E...

A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-47167: A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7...

A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-46683: A post authentication command injection vulnerability exists when configuring the wireguard VPN functional...

A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-42664: A post authentication command injection vulnerability exists when setting up the PPTP global configuration...

A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published Feb 6, 2024 · Updated Nov 4, 2025

Medium · CVSS 5.4

CVE-2023-41708: References to the "app loader" functionality could contain redirects to unexpected locations.

References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

Medium · CVSS 6.5

CVE-2023-41707: Processing of user-defined mail search expressions is not limited.

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

Medium · CVSS 6.5

CVE-2023-41706: Processing time of drive search expressions now gets monitored, and the related request is terminated if a...

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

Medium · CVSS 6.5

CVE-2023-41705: Processing of user-defined DAV user-agent strings is not limited.

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

High · CVSS 7.1

CVE-2023-41704: Processing of CID references at E-Mail can be abused to inject malicious script code that passes the saniti...

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

Medium · CVSS 6.1

CVE-2023-41703: User ID references at mentions in document comments were not correctly sanitized.

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

Published Feb 12, 2024 · Updated Nov 4, 2025

Medium · CVSS 5.9

CVE-2023-39541: A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC...

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv6 ICMPv6 packet.

Published Feb 20, 2024 · Updated Nov 4, 2025

Medium · CVSS 5.9

CVE-2023-39540: A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC...

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet.

Published Feb 20, 2024 · Updated Nov 4, 2025

High · CVSS 8.7

CVE-2023-38562: A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TC...

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

Published Feb 20, 2024 · Updated Nov 4, 2025

High · CVSS 7.2

CVE-2023-36498: A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER...

A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.

Published Feb 6, 2024 · Updated Nov 4, 2025

Critical · CVSS 9.1

CVE-2023-5841: OpenEXR Heap Overflow in Scanline Deep Data Parsing

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Published Feb 1, 2024 · Updated Nov 4, 2025

High · CVSS 7.3

CVE-2023-43016: IBM Security Access Manager Container unauthorized access

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154.

Published Feb 3, 2024 · Updated Nov 3, 2025

Medium · CVSS 6.2

CVE-2023-32329: IBM Security Access Manager Container improper file validation

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.

Published Feb 3, 2024 · Updated Nov 3, 2025

High · CVSS 7.1

CVE-2023-32327: IBM Security Access Manager Container XML external entity injection

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 254783.

Published Feb 3, 2024 · Updated Nov 3, 2025

Medium · CVSS 6.5

CVE-2023-31006: IBM Security Access Manager Container denial of service

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.

Published Feb 3, 2024 · Updated Nov 3, 2025

Medium · CVSS 6.2

CVE-2023-31005: IBM Security Access Manager Container privilege escalation

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.

Published Feb 3, 2024 · Updated Nov 3, 2025

High · CVSS 8.3

CVE-2023-31004: IBM Security Access Manager Container gain access

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote attacker to gain access to the underlying system using man in the middle techniques. IBM X-Force ID: 254765.

Published Feb 3, 2024 · Updated Nov 3, 2025

High · CVSS 7.5

CVE-2023-30999: IBM Security Access Manager denial of service

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.

Published Feb 3, 2024 · Updated Nov 3, 2025

Unknown · CVSS Not scored

CVE-2023-24998: Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

Published Feb 20, 2023 · Updated Nov 3, 2025

Medium · CVSS 4.8

CVE-2023-23931: Cipher.update_into can corrupt memory in pyca cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

Published Feb 7, 2023 · Updated Nov 3, 2025

High · CVSS 7.8

CVE-2023-52926: io_uring/rw: split io_read() into a helper

In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return). This can lead to a potential use-after-free when the completion via io_rw_done runs at separate context.

Published Feb 24, 2025 · Updated Nov 3, 2025

High · CVSS 7.2 · CISA KEV

CVE-2023-0669: Fortra GoAnywhere MFT License Response Servlet Command Injection

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

Published Feb 6, 2023 · Updated Oct 21, 2025

High · CVSS 8.8 · CISA KEV

CVE-2023-23529: A type confusion issue was addressed with improved checks.

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Published Feb 27, 2023 · Updated Oct 21, 2025

Medium · CVSS 4.4

CVE-2023-52433: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC for such elements otherwise commit path might walk over an already released object. Once transaction is finished, async GC will collect such expired element.

Published Feb 20, 2024 · Updated Oct 1, 2025

Medium · CVSS 5.5

CVE-2023-52453: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume When the optional PRE_COPY support was added to speed up the device compatibility check, it failed to update the saving/resuming data pointers based on the fd offset. This results in migration data corruption and when the device gets started on the destination the following error is reported in some cases, [ 478.907684] arm-smmu-v3 arm-smmu-v3.2.auto: event 0x10 received: [ 478.913691] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000310200000010 [ 478.919603] arm-smmu-v3 arm-smmu-v3.2.auto: 0x000002088000007f [ 478.925515] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000 [ 478.931425] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000 [ 478.947552] hisi_zip 0000:31:00.0: qm_axi_rresp [error status=0x1] found [ 478.955930] hisi_zip 0000:31:00.0: qm_db_timeout [error status=0x400] found [ 478.955944] hisi_zip 0000:31:00.0: qm sq doorbell timeout in function 2

Published Feb 23, 2024 · Updated Oct 1, 2025

Medium · CVSS 5.5

CVE-2023-52442: ksmbd: validate session id and tree id in compound request

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header in a compound request. if `SMB2_TREE_CONNECT_HE` is the first command in compound request, will return 0, i.e. The tree id check is skipped. This patch use ksmbd_req_buf_next() to get current command in compound.

Published Feb 21, 2024 · Updated Oct 1, 2025