Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1005/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2021-4432(opens NVD record) | Medium | 5.3 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250719. | Jan 16, 2024 |
| CVE-2024-0567(opens NVD record) | High | 7.5 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. | Jan 16, 2024 |
| CVE-2024-0232(opens NVD record) | Medium | 4.7 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service. | Jan 16, 2024 |
| CVE-2024-0553(opens NVD record) | High | 7.5 | A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981. | Jan 16, 2024 |
| CVE-2023-52106(opens NVD record) | Medium | 4.4 | Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability. | Jan 16, 2024 |
| CVE-2023-52105(opens NVD record) | High | 7.5 | The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. | Jan 16, 2024 |
| CVE-2023-52104(opens NVD record) | High | 7.5 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-52103(opens NVD record) | Critical | 9.8 | Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read. | Jan 16, 2024 |
| CVE-2023-52102(opens NVD record) | High | 7.5 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-52101(opens NVD record) | Critical | 9.1 | Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity. | Jan 16, 2024 |
| CVE-2023-52100(opens NVD record) | High | 7.5 | The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability. | Jan 16, 2024 |
| CVE-2023-52099(opens NVD record) | High | 7.5 | Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-34063(opens NVD record) | Critical | 9.9 | Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows. | Jan 16, 2024 |
| CVE-2023-52116(opens NVD record) | High | 7.5 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | Jan 16, 2024 |
| CVE-2023-52115(opens NVD record) | High | 7.5 | The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions. | Jan 16, 2024 |
| CVE-2023-52114(opens NVD record) | High | 7.5 | Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. | Jan 16, 2024 |
| CVE-2023-52108(opens NVD record) | High | 7.5 | Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability. | Jan 16, 2024 |
| CVE-2023-52107(opens NVD record) | High | 7.5 | Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-52098(opens NVD record) | High | 7.5 | Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability. | Jan 16, 2024 |
| CVE-2023-52113(opens NVD record) | High | 7.5 | launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability. | Jan 16, 2024 |
| CVE-2023-52112(opens NVD record) | Medium | 5.3 | Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Jan 16, 2024 |
| CVE-2023-52111(opens NVD record) | High | 7.5 | Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity. | Jan 16, 2024 |
| CVE-2023-52110(opens NVD record) | High | 7.5 | The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability. | Jan 16, 2024 |
| CVE-2023-52109(opens NVD record) | High | 7.5 | Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-4566(opens NVD record) | High | 7.5 | Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-44117(opens NVD record) | High | 7.5 | Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | Jan 16, 2024 |
| CVE-2023-44112(opens NVD record) | High | 7.5 | Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality. | Jan 16, 2024 |
| CVE-2024-22428(opens NVD record) | High | 7.0 | Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity. | Jan 16, 2024 |
| CVE-2023-51810(opens NVD record) | High | 7.5 | SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module. | Jan 16, 2024 |
| CVE-2023-49107(opens NVD record) | Medium | 5.3 | Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04. | Jan 16, 2024 |
| CVE-2023-49106(opens NVD record) | Medium | 4.6 | Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04. | Jan 16, 2024 |
| CVE-2024-0565(opens NVD record) | Medium | 6.8 | An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service. | Jan 15, 2024 |
| CVE-2024-0562(opens NVD record) | High | 7.8 | A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation work after this has completed, which can result in the timer attempting to access the recently freed bdi_writeback. | Jan 15, 2024 |
| CVE-2024-20721(opens NVD record) | Medium | 5.5 | Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 15, 2024 |
| CVE-2024-20709(opens NVD record) | Medium | 5.5 | Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 15, 2024 |
| CVE-2023-4001(opens NVD record) | Medium | 6.8 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package. | Jan 15, 2024 |
| CVE-2023-6915(opens NVD record) | Medium | 6.2 | A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. | Jan 15, 2024 |
| CVE-2024-23301(opens NVD record) | Medium | 5.5 | Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. | Jan 12, 2024 |
| CVE-2023-49647(opens NVD record) | High | 8.8 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access. | Jan 12, 2024 |
| CVE-2023-6683(opens NVD record) | Medium | 6.5 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service. | Jan 12, 2024 |
| CVE-2023-31035(opens NVD record) | High | 7.5 | NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure. | Jan 12, 2024 |
| CVE-2023-31034(opens NVD record) | Medium | 6.6 | NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2023-31033(opens NVD record) | Medium | 6.8 | NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2023-31032(opens NVD record) | High | 7.5 | NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service. | Jan 12, 2024 |
| CVE-2023-31031(opens NVD record) | Medium | 4.2 | NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2023-31030(opens NVD record) | Critical | 9.3 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2023-31029(opens NVD record) | Critical | 9.3 | NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2023-31025(opens NVD record) | Medium | 6.5 | NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure. | Jan 12, 2024 |
| CVE-2023-31024(opens NVD record) | Critical | 9.0 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering. | Jan 12, 2024 |
| CVE-2024-21887(opens NVD record) | Critical | 9.1 | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance. | Jan 12, 2024 |