Common Vulnerabilities and Exposures

View Source

CVE-2023-36769

Microsoft OneNote Spoofing Vulnerability

  • 2023-11-06T23:15:10Z
View Source

CVE-2023-36677

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.

  • 2023-11-03T23:15:08Z
View Source

CVE-2023-36621

An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

  • 2023-11-03T04:15:21Z
View Source

CVE-2023-36620

An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.

  • 2023-11-03T04:15:21Z
View Source

CVE-2023-36529

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.

  • 2023-11-03T17:15:08Z
View Source

CVE-2023-36409

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • 2023-11-07T00:15:07Z
View Source

CVE-2023-36034

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • 2023-11-03T01:15:08Z
View Source

CVE-2023-36029

Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • 2023-11-03T01:15:07Z

Copyright @2023 ZAMBIA CIRT