Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1008/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-20658(opens NVD record) | High | 7.8 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20657(opens NVD record) | High | 7.0 | Windows Group Policy Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20656(opens NVD record) | High | 7.8 | Visual Studio Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20655(opens NVD record) | Medium | 6.6 | Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20654(opens NVD record) | High | 8.0 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20653(opens NVD record) | High | 7.8 | Microsoft Common Log File System Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20652(opens NVD record) | High | 8.1 | Windows HTML Platforms Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-0057(opens NVD record) | Critical | 9.1 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-0056(opens NVD record) | High | 8.7 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-0213(opens NVD record) | High | 8.2 | A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly. | Jan 9, 2024 |
| CVE-2024-0206(opens NVD record) | High | 7.1 | A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files | Jan 9, 2024 |
| CVE-2022-28975(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field. | Jan 9, 2024 |
| CVE-2023-39336(opens NVD record) | High | 8.8 | An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server. | Jan 9, 2024 |
| CVE-2023-27098(opens NVD record) | High | 7.5 | TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel. | Jan 9, 2024 |
| CVE-2023-27000(opens NVD record) | Medium | 6.1 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s). | Jan 9, 2024 |
| CVE-2023-26999(opens NVD record) | Critical | 9.8 | An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file. | Jan 9, 2024 |
| CVE-2023-26998(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page. | Jan 9, 2024 |
| CVE-2024-21646(opens NVD record) | Critical | 9.8 | Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched in release 2024-01-01. | Jan 9, 2024 |
| CVE-2023-50643(opens NVD record) | Critical | 9.8 | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components. | Jan 9, 2024 |
| CVE-2023-49961(opens NVD record) | High | 7.5 | WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure. | Jan 8, 2024 |
| CVE-2023-47890(opens NVD record) | High | 8.8 | pyLoad 0.5.0 is vulnerable to Unrestricted File Upload. | Jan 8, 2024 |
| CVE-2021-3600(opens NVD record) | High | 7.8 | It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code. | Jan 8, 2024 |
| CVE-2022-2586(opens NVD record) | Medium | 5.3 | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. | Jan 8, 2024 |
| CVE-2023-47211(opens NVD record) | Critical | 9.1 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | Jan 8, 2024 |
| CVE-2023-7224(opens NVD record) | High | 7.8 | OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable | Jan 8, 2024 |
| CVE-2023-47140(opens NVD record) | Medium | 4.0 | IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls. | Jan 8, 2024 |
| CVE-2023-50948(opens NVD record) | Medium | 6.5 | IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671. | Jan 8, 2024 |
| CVE-2023-47145(opens NVD record) | High | 8.4 | IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402. | Jan 7, 2024 |
| CVE-2024-22051(opens NVD record) | Critical | 9.8 | CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns. | Jan 4, 2024 |
| CVE-2024-22050(opens NVD record) | High | 7.5 | Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs. | Jan 4, 2024 |
| CVE-2024-22049(opens NVD record) | Medium | 5.3 | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. | Jan 4, 2024 |
| CVE-2024-22048(opens NVD record) | Medium | 6.1 | govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. | Jan 4, 2024 |
| CVE-2024-22047(opens NVD record) | Low | 3.1 | A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user. | Jan 4, 2024 |
| CVE-2024-0241(opens NVD record) | High | 7.5 | encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter. | Jan 4, 2024 |
| CVE-2023-6944(opens NVD record) | Medium | 5.7 | A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately. | Jan 4, 2024 |
| CVE-2024-0217(opens NVD record) | Low | 3.3 | A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost. | Jan 3, 2024 |
| CVE-2023-6004(opens NVD record) | Medium | 4.8 | A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter. | Jan 3, 2024 |
| CVE-2024-21911(opens NVD record) | Medium | 6.1 | TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser. | Jan 3, 2024 |
| CVE-2024-21910(opens NVD record) | Medium | 6.1 | TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser. | Jan 3, 2024 |
| CVE-2024-21909(opens NVD record) | High | 7.5 | PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in PeterO.Cbor. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition. | Jan 3, 2024 |
| CVE-2024-21908(opens NVD record) | Medium | 6.1 | TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser. | Jan 3, 2024 |
| CVE-2024-21907(opens NVD record) | High | 7.5 | Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition. | Jan 3, 2024 |
| CVE-2023-45559(opens NVD record) | High | 8.2 | An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | Jan 3, 2024 |
| CVE-2023-37607(opens NVD record) | High | 7.5 | Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter. | Jan 3, 2024 |
| CVE-2023-37608(opens NVD record) | High | 7.5 | An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password. | Jan 3, 2024 |
| CVE-2020-26625(opens NVD record) | Low | 3.8 | A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal. | Jan 2, 2024 |
| CVE-2020-26624(opens NVD record) | Low | 3.8 | A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal. | Jan 2, 2024 |
| CVE-2020-26623(opens NVD record) | Low | 3.8 | SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal. | Jan 2, 2024 |
| CVE-2023-47458(opens NVD record) | Critical | 9.8 | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. | Jan 2, 2024 |
| CVE-2023-7192(opens NVD record) | Medium | 5.5 | A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow. | Jan 2, 2024 |