Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1007/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-37932(opens NVD record) | Medium | 6.5 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests | Jan 10, 2024 |
| CVE-2024-20715(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20714(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20713(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20712(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20711(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20710(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2023-5455(opens NVD record) | Medium | 6.5 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | Jan 10, 2024 |
| CVE-2024-0310(opens NVD record) | Medium | 6.1 | A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration. | Jan 10, 2024 |
| CVE-2024-21643(opens NVD record) | High | 7.1 | IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for the `SignedHttpRequest`protocol. This raises the possibility to make any remote or local `HTTP GET` request. The vulnerability has been fixed in Microsoft.IdentityModel.Protocols.SignedHttpRequest. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher. | Jan 10, 2024 |
| CVE-2023-6476(opens NVD record) | Medium | 6.5 | A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node. | Jan 9, 2024 |
| CVE-2024-21319(opens NVD record) | Medium | 6.8 | Microsoft Identity Denial of service vulnerability | Jan 9, 2024 |
| CVE-2024-21325(opens NVD record) | High | 7.8 | Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21320(opens NVD record) | Medium | 6.5 | Windows Themes Spoofing Vulnerability | Jan 9, 2024 |
| CVE-2024-21318(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21316(opens NVD record) | Medium | 6.1 | Windows Server Key Distribution Service Security Feature Bypass | Jan 9, 2024 |
| CVE-2024-21314(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21313(opens NVD record) | Medium | 5.3 | Windows TCP/IP Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21312(opens NVD record) | High | 7.5 | .NET Framework Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-21311(opens NVD record) | Medium | 5.5 | Windows Cryptographic Services Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21310(opens NVD record) | High | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-21309(opens NVD record) | High | 7.8 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-21307(opens NVD record) | High | 7.5 | Remote Desktop Client Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21306(opens NVD record) | Medium | 5.7 | Microsoft Bluetooth Driver Spoofing Vulnerability | Jan 9, 2024 |
| CVE-2024-21305(opens NVD record) | Medium | 4.4 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-20700(opens NVD record) | High | 7.5 | Windows Hyper-V Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20699(opens NVD record) | Medium | 5.5 | Windows Hyper-V Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-20698(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20697(opens NVD record) | High | 7.3 | Windows libarchive Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20696(opens NVD record) | High | 7.3 | Windows libarchive Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20694(opens NVD record) | Medium | 5.5 | Windows CoreMessaging Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-20692(opens NVD record) | Medium | 5.7 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-20691(opens NVD record) | Medium | 4.7 | Windows Themes Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-20690(opens NVD record) | Medium | 6.5 | Windows Nearby Sharing Spoofing Vulnerability | Jan 9, 2024 |
| CVE-2024-20687(opens NVD record) | High | 7.5 | Microsoft AllJoyn API Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-20686(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20683(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20682(opens NVD record) | High | 7.8 | Windows Cryptographic Services Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20681(opens NVD record) | High | 7.8 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20680(opens NVD record) | Medium | 6.5 | Windows Message Queuing Client (MSMQC) Information Disclosure | Jan 9, 2024 |
| CVE-2024-20677(opens NVD record) | High | 7.8 | A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update. | Jan 9, 2024 |
| CVE-2024-20676(opens NVD record) | High | 8.0 | Azure Storage Mover Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20674(opens NVD record) | High | 8.8 | Windows Kerberos Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-20672(opens NVD record) | High | 7.5 | .NET Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-20666(opens NVD record) | Medium | 6.6 | BitLocker Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-20664(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-20663(opens NVD record) | Medium | 6.5 | Windows Message Queuing Client (MSMQC) Information Disclosure | Jan 9, 2024 |
| CVE-2024-20662(opens NVD record) | Medium | 4.9 | Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-20661(opens NVD record) | High | 7.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-20660(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing Information Disclosure Vulnerability | Jan 9, 2024 |