Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1010/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-50988(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function. | Dec 20, 2023 |
| CVE-2023-50987(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function. | Dec 20, 2023 |
| CVE-2023-50986(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. | Dec 20, 2023 |
| CVE-2023-50985(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function. | Dec 20, 2023 |
| CVE-2023-50984(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function. | Dec 20, 2023 |
| CVE-2023-50983(opens NVD record) | Critical | 9.8 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. | Dec 20, 2023 |
| CVE-2022-44684(opens NVD record) | Medium | 6.5 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | Dec 20, 2023 |
| CVE-2023-35895(opens NVD record) | Medium | 6.3 | IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116. | Dec 20, 2023 |
| CVE-2023-6784(opens NVD record) | Medium | 4.7 | A malicious user could potentially use the Sitefinity system for the distribution of phishing emails. | Dec 20, 2023 |
| CVE-2023-47707(opens NVD record) | Medium | 5.4 | IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522. | Dec 20, 2023 |
| CVE-2023-47705(opens NVD record) | Medium | 4.3 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228. | Dec 20, 2023 |
| CVE-2023-47703(opens NVD record) | Medium | 5.3 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197. | Dec 20, 2023 |
| CVE-2023-47702(opens NVD record) | Medium | 4.3 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196. | Dec 20, 2023 |
| CVE-2023-47706(opens NVD record) | Medium | 6.6 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. | Dec 20, 2023 |
| CVE-2023-47704(opens NVD record) | Medium | 4.0 | IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220. | Dec 20, 2023 |
| CVE-2023-47161(opens NVD record) | Medium | 5.3 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. IBM X-Force ID: 270799. | Dec 20, 2023 |
| CVE-2023-42013(opens NVD record) | Medium | 5.3 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510. | Dec 20, 2023 |
| CVE-2023-42012(opens NVD record) | Medium | 6.2 | An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509. | Dec 20, 2023 |
| CVE-2023-45172(opens NVD record) | Medium | 6.2 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970. | Dec 19, 2023 |
| CVE-2023-47146(opens NVD record) | Medium | 4.9 | IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372. | Dec 19, 2023 |
| CVE-2023-46804(opens NVD record) | High | 7.5 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS). | Dec 19, 2023 |
| CVE-2023-46803(opens NVD record) | High | 7.5 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS). | Dec 19, 2023 |
| CVE-2023-46266(opens NVD record) | Critical | 9.1 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | Dec 19, 2023 |
| CVE-2023-46265(opens NVD record) | Critical | 9.8 | An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF). | Dec 19, 2023 |
| CVE-2023-46264(opens NVD record) | Critical | 9.8 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | Dec 19, 2023 |
| CVE-2023-46263(opens NVD record) | Critical | 9.8 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution. | Dec 19, 2023 |
| CVE-2023-46262(opens NVD record) | High | 7.5 | An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server. | Dec 19, 2023 |
| CVE-2023-46261(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46260(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46259(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46258(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46257(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46225(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46224(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46223(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46222(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46221(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46220(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46217(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-46216(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2023-41727(opens NVD record) | Critical | 9.8 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | Dec 19, 2023 |
| CVE-2021-22962(opens NVD record) | Critical | 9.1 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | Dec 19, 2023 |
| CVE-2023-6931(opens NVD record) | High | 7.8 | A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b. | Dec 19, 2023 |
| CVE-2023-42015(opens NVD record) | Medium | 4.3 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512. | Dec 19, 2023 |
| CVE-2023-6918(opens NVD record) | Low | 3.7 | A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection. | Dec 19, 2023 |
| CVE-2023-6927(opens NVD record) | Medium | 4.6 | A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134. | Dec 18, 2023 |
| CVE-2023-40691(opens NVD record) | Medium | 4.9 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805. | Dec 18, 2023 |
| CVE-2023-47741(opens NVD record) | Medium | 5.3 | IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532. | Dec 18, 2023 |
| CVE-2023-51384(opens NVD record) | Medium | 5.5 | In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys. | Dec 18, 2023 |
| CVE-2023-6691(opens NVD record) | High | 7.8 | Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges. | Dec 18, 2023 |