Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1000/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-22319(opens NVD record) | High | 8.1 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. | Feb 2, 2024 |
| CVE-2023-46159(opens NVD record) | Low | 2.6 | IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906. | Feb 2, 2024 |
| CVE-2024-22903(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. | Feb 2, 2024 |
| CVE-2024-22902(opens NVD record) | Critical | 9.8 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. | Feb 2, 2024 |
| CVE-2024-22901(opens NVD record) | Critical | 9.8 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. | Feb 2, 2024 |
| CVE-2024-22900(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. | Feb 2, 2024 |
| CVE-2024-22899(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. | Feb 2, 2024 |
| CVE-2023-50962(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004. | Feb 2, 2024 |
| CVE-2023-50941(opens NVD record) | Medium | 6.3 | IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131. | Feb 2, 2024 |
| CVE-2023-50938(opens NVD record) | Medium | 6.5 | IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 275128. | Feb 2, 2024 |
| CVE-2023-50935(opens NVD record) | Medium | 6.5 | IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115. | Feb 2, 2024 |
| CVE-2023-50934(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114. | Feb 2, 2024 |
| CVE-2023-50328(opens NVD record) | Low | 3.7 | IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110. | Feb 2, 2024 |
| CVE-2023-48793(opens NVD record) | Critical | 9.8 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | Feb 2, 2024 |
| CVE-2023-48792(opens NVD record) | Critical | 9.8 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | Feb 2, 2024 |
| CVE-2023-46344(opens NVD record) | Medium | 5.4 | A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base. | Feb 2, 2024 |
| CVE-2023-32333(opens NVD record) | Medium | 6.5 | IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073. | Feb 2, 2024 |
| CVE-2024-21399(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Feb 2, 2024 |
| CVE-2023-50940(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130. | Feb 2, 2024 |
| CVE-2023-50937(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117. | Feb 2, 2024 |
| CVE-2023-50936(opens NVD record) | Medium | 6.3 | IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116. | Feb 2, 2024 |
| CVE-2023-50933(opens NVD record) | Medium | 6.1 | IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113. | Feb 2, 2024 |
| CVE-2023-50327(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: 275109. | Feb 2, 2024 |
| CVE-2023-50326(opens NVD record) | High | 7.5 | IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107. | Feb 2, 2024 |
| CVE-2023-50939(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129. | Feb 2, 2024 |
| CVE-2023-36496(opens NVD record) | High | 7.7 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | Feb 1, 2024 |
| CVE-2024-22449(opens NVD record) | Medium | 6.6 | Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access. | Feb 1, 2024 |
| CVE-2024-22430(opens NVD record) | Medium | 5.5 | Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service. | Feb 1, 2024 |
| CVE-2024-21626(opens NVD record) | High | 8.6 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. | Jan 31, 2024 |
| CVE-2024-21893(opens NVD record) | High | 8.2 | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. | Jan 31, 2024 |
| CVE-2024-21888(opens NVD record) | High | 8.8 | A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. | Jan 31, 2024 |
| CVE-2024-0833(opens NVD record) | High | 7.8 | In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system. | Jan 31, 2024 |
| CVE-2024-0832(opens NVD record) | High | 7.8 | In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system. | Jan 31, 2024 |
| CVE-2024-0219(opens NVD record) | High | 7.8 | In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system. | Jan 31, 2024 |
| CVE-2023-5992(opens NVD record) | Medium | 5.6 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. | Jan 31, 2024 |
| CVE-2024-1086(opens NVD record) | High | 7.8 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660. | Jan 31, 2024 |
| CVE-2024-0589(opens NVD record) | Medium | 5.4 | Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry. | Jan 31, 2024 |
| CVE-2024-22236(opens NVD record) | Low | 3.3 | In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency. | Jan 31, 2024 |
| CVE-2024-0914(opens NVD record) | Medium | 5.9 | A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key. | Jan 31, 2024 |
| CVE-2024-21388(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Jan 30, 2024 |
| CVE-2024-0564(opens NVD record) | Medium | 5.3 | A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's "max page share". Through these operations, the attacker can leak the victim's page. | Jan 30, 2024 |
| CVE-2024-21488(opens NVD record) | High | 7.3 | Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on. | Jan 30, 2024 |
| CVE-2023-4554(opens NVD record) | Medium | 4.9 | Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor is vulnerable to XML External Entity Processing (XXE), allowing an authenticated user to upload specially crafted XML files to induce server-side request forgery, disclose files local to the server that processes them. This issue affects AppBuilder: from 21.2 before 23.2. | Jan 29, 2024 |
| CVE-2023-4553(opens NVD record) | Medium | 5.3 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects AppBuilder: from 21.2 before 23.2. | Jan 29, 2024 |
| CVE-2023-4552(opens NVD record) | Medium | 5.5 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system. This issue affects AppBuilder: from 21.2 before 23.2. | Jan 29, 2024 |
| CVE-2023-4551(opens NVD record) | High | 7.2 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the executing process. This issue affects AppBuilder: from 21.2 before 23.2. | Jan 29, 2024 |
| CVE-2023-4550(opens NVD record) | High | 7.5 | Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. This issue affects AppBuilder: from 21.2 before 23.2. | Jan 29, 2024 |
| CVE-2024-23940(opens NVD record) | High | 7.8 | Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system. | Jan 29, 2024 |
| CVE-2023-40551(opens NVD record) | Medium | 5.1 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. | Jan 29, 2024 |
| CVE-2023-40550(opens NVD record) | Medium | 5.5 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. | Jan 29, 2024 |