CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-0135

    Last Modified: 5 May 2025

    Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    8.8
    High

    CVE-2023-0137

    Last Modified: 5 May 2025

    Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    7
    High

    CVE-2023-21532

    Last Modified: 1 Jan 2025

    Windows GDI Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    8.1
    High

    CVE-2023-21548

    Last Modified: 1 Jan 2025

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    5.5
    Medium

    CVE-2023-21550

    Last Modified: 1 Jan 2025

    Windows Cryptographic Information Disclosure Vulnerability

    Published: 10 Jan 2023
    6.1
    Medium

    CVE-2021-46871

    Last Modified: 9 Apr 2025

    tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.

    Published: 10 Jan 2023
    7.5
    High

    CVE-2022-46449

    Last Modified: 9 Apr 2025

    An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 10 Jan 2023
    5.3
    Medium

    CVE-2022-30332

    Last Modified: 28 Aug 2025

    In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.

    Published: 10 Jan 2023
    5.5
    Medium

    CVE-2022-36442

    Last Modified: 30 May 2025

    An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.

    Published: 10 Jan 2023
    4.3
    Medium

    CVE-2022-38482

    Last Modified: 30 May 2025

    A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.

    Published: 10 Jan 2023
    9.6
    Critical

    CVE-2022-38490

    Last Modified: 9 Apr 2025

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.

    Published: 10 Jan 2023
    8.2
    High

    CVE-2022-38491

    Last Modified: 9 Apr 2025

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.

    Published: 10 Jan 2023
    7.7
    High

    CVE-2022-38492

    Last Modified: 9 Apr 2025

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21524

    Last Modified: 12 Apr 2025

    Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    5.3
    Medium

    CVE-2023-21525

    Last Modified: 1 Jan 2025

    Remote Procedure Call Runtime Denial of Service Vulnerability

    Published: 10 Jan 2023
    7.5
    High

    CVE-2023-21527

    Last Modified: 1 Jan 2025

    Windows iSCSI Service Denial of Service Vulnerability

    Published: 10 Jan 2023
    8.1
    High

    CVE-2023-21535

    Last Modified: 1 Jan 2025

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21537

    Last Modified: 1 Jan 2025

    Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    5.5
    Medium

    CVE-2023-21540

    Last Modified: 1 Jan 2025

    Windows Cryptographic Information Disclosure Vulnerability

    Published: 10 Jan 2023
    8.1
    High

    CVE-2023-21546

    Last Modified: 1 Jan 2025

    Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    7.5
    High

    CVE-2023-21547

    Last Modified: 1 Jan 2025

    Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21551

    Last Modified: 1 Jan 2025

    Microsoft Cryptographic Services Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21552

    Last Modified: 1 Jan 2025

    Windows GDI Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    8.1
    High

    CVE-2023-21555

    Last Modified: 1 Jan 2025

    Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    8.1
    High

    CVE-2023-21556

    Last Modified: 1 Jan 2025

    Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    7.5
    High

    CVE-2023-21557

    Last Modified: 1 Jan 2025

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

    Published: 10 Jan 2023
    6.6
    Medium

    CVE-2023-21560

    Last Modified: 1 Jan 2025

    Windows Boot Manager Security Feature Bypass Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21561

    Last Modified: 1 Jan 2025

    Microsoft Cryptographic Services Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21680

    Last Modified: 1 Jan 2025

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21746

    Last Modified: 1 Jan 2025

    Windows NTLM Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21747

    Last Modified: 1 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21749

    Last Modified: 1 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.1
    High

    CVE-2023-21752

    Last Modified: 1 Jan 2025

    Windows Backup Service Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21754

    Last Modified: 12 Apr 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.5
    High

    CVE-2023-21758

    Last Modified: 1 Jan 2025

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

    Published: 10 Jan 2023
    8
    High

    CVE-2023-21762

    Last Modified: 28 Feb 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21765

    Last Modified: 1 Jan 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21767

    Last Modified: 1 Jan 2025

    Windows Overlay Filter Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7
    High

    CVE-2023-21771

    Last Modified: 12 Apr 2025

    Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21779

    Last Modified: 1 Jan 2025

    Visual Studio Code Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    8.8
    High

    CVE-2023-0129

    Last Modified: 5 May 2025

    Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and specific interactions. (Chromium security severity: High)

    Published: 10 Jan 2023
    —
    Unknown

    CVE-2023-0161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jan 2023
    7.8
    High

    CVE-2023-21789

    Last Modified: 1 Jan 2025

    3D Builder Remote Code Execution Vulnerability

    Published: 10 Jan 2023
    8.8
    High

    CVE-2022-46610

    Last Modified: 9 Apr 2025

    72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 10 Jan 2023
    6.5
    Medium

    CVE-2023-0130

    Last Modified: 20 Mar 2025

    Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    6.5
    Medium

    CVE-2023-0131

    Last Modified: 20 Mar 2025

    Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    6.5
    Medium

    CVE-2023-0132

    Last Modified: 20 Mar 2025

    Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    6.5
    Medium

    CVE-2023-0133

    Last Modified: 20 Mar 2025

    Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    8.8
    High

    CVE-2023-0134

    Last Modified: 5 May 2025

    Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023
    8.8
    High

    CVE-2023-0136

    Last Modified: 5 May 2025

    Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Jan 2023