CVE-2023-0135
Last Modified: 5 May 2025Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0137
Last Modified: 5 May 2025Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-21532
Last Modified: 1 Jan 2025Windows GDI Elevation of Privilege Vulnerability
CVE-2023-21548
Last Modified: 1 Jan 2025Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2023-21550
Last Modified: 1 Jan 2025Windows Cryptographic Information Disclosure Vulnerability
CVE-2021-46871
Last Modified: 9 Apr 2025tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
CVE-2022-46449
Last Modified: 9 Apr 2025An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2022-30332
Last Modified: 28 Aug 2025In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
CVE-2022-36442
Last Modified: 30 May 2025An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.
CVE-2022-38482
Last Modified: 30 May 2025A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.
CVE-2022-38490
Last Modified: 9 Apr 2025An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.
CVE-2022-38491
Last Modified: 9 Apr 2025An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.
CVE-2022-38492
Last Modified: 9 Apr 2025An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.
CVE-2023-21524
Last Modified: 12 Apr 2025Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
CVE-2023-21525
Last Modified: 1 Jan 2025Remote Procedure Call Runtime Denial of Service Vulnerability
CVE-2023-21527
Last Modified: 1 Jan 2025Windows iSCSI Service Denial of Service Vulnerability
CVE-2023-21535
Last Modified: 1 Jan 2025Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2023-21537
Last Modified: 1 Jan 2025Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2023-21540
Last Modified: 1 Jan 2025Windows Cryptographic Information Disclosure Vulnerability
CVE-2023-21546
Last Modified: 1 Jan 2025Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
CVE-2023-21547
Last Modified: 1 Jan 2025Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2023-21551
Last Modified: 1 Jan 2025Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2023-21552
Last Modified: 1 Jan 2025Windows GDI Elevation of Privilege Vulnerability
CVE-2023-21555
Last Modified: 1 Jan 2025Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
CVE-2023-21556
Last Modified: 1 Jan 2025Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
CVE-2023-21557
Last Modified: 1 Jan 2025Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2023-21560
Last Modified: 1 Jan 2025Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2023-21561
Last Modified: 1 Jan 2025Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2023-21680
Last Modified: 1 Jan 2025Windows Win32k Elevation of Privilege Vulnerability
CVE-2023-21746
Last Modified: 1 Jan 2025Windows NTLM Elevation of Privilege Vulnerability
CVE-2023-21747
Last Modified: 1 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21749
Last Modified: 1 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21752
Last Modified: 1 Jan 2025Windows Backup Service Elevation of Privilege Vulnerability
CVE-2023-21754
Last Modified: 12 Apr 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21758
Last Modified: 1 Jan 2025Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVE-2023-21762
Last Modified: 28 Feb 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21765
Last Modified: 1 Jan 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21767
Last Modified: 1 Jan 2025Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2023-21771
Last Modified: 12 Apr 2025Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
CVE-2023-21779
Last Modified: 1 Jan 2025Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-0129
Last Modified: 5 May 2025Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and specific interactions. (Chromium security severity: High)
CVE-2023-0161
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
CVE-2023-21789
Last Modified: 1 Jan 20253D Builder Remote Code Execution Vulnerability
CVE-2022-46610
Last Modified: 9 Apr 202572crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2023-0130
Last Modified: 20 Mar 2025Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0131
Last Modified: 20 Mar 2025Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0132
Last Modified: 20 Mar 2025Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0133
Last Modified: 20 Mar 2025Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0134
Last Modified: 5 May 2025Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0136
Last Modified: 5 May 2025Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect security UI via a crafted HTML page. (Chromium security severity: Medium)
