Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 1013/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-47074(opens NVD record) | High | 7.8 | Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 13, 2023 |
| CVE-2023-47063(opens NVD record) | High | 7.8 | Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 13, 2023 |
| CVE-2023-44252(opens NVD record) | High | 8.8 | ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values. | Dec 13, 2023 |
| CVE-2023-44251(opens NVD record) | High | 8.3 | ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read and delete arbitrary file of the system via crafted HTTP or HTTPs requests. | Dec 13, 2023 |
| CVE-2022-22942(opens NVD record) | High | 7.8 | The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer. | Dec 13, 2023 |
| CVE-2023-47536(opens NVD record) | Low | 3.1 | An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update. | Dec 13, 2023 |
| CVE-2023-6478(opens NVD record) | High | 7.6 | A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. | Dec 13, 2023 |
| CVE-2023-6377(opens NVD record) | High | 7.8 | A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved. | Dec 13, 2023 |
| CVE-2023-48791(opens NVD record) | High | 8.8 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field. | Dec 13, 2023 |
| CVE-2023-48782(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters | Dec 13, 2023 |
| CVE-2023-46713(opens NVD record) | Medium | 5.3 | An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application. | Dec 13, 2023 |
| CVE-2023-45587(opens NVD record) | Low | 3.5 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions allows attacker to execute unauthorized code or commands via crafted HTTP requests | Dec 13, 2023 |
| CVE-2023-41844(opens NVD record) | Low | 3.5 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.4 and above allows attacker to execute unauthorized code or commands via crafted HTTP requests in capture traffic endpoint. | Dec 13, 2023 |
| CVE-2023-41678(opens NVD record) | High | 8.8 | A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request. | Dec 13, 2023 |
| CVE-2023-41673(opens NVD record) | High | 7.1 | An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests. | Dec 13, 2023 |
| CVE-2023-40716(opens NVD record) | Medium | 6.7 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup . | Dec 13, 2023 |
| CVE-2023-36639(opens NVD record) | High | 7.2 | A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands via specially crafted API requests. | Dec 13, 2023 |
| CVE-2022-27488(opens NVD record) | High | 8.3 | A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests. | Dec 13, 2023 |
| CVE-2023-6753(opens NVD record) | High | 8.8 | Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. | Dec 13, 2023 |
| CVE-2023-6710(opens NVD record) | Medium | 5.4 | A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page. | Dec 12, 2023 |
| CVE-2023-5764(opens NVD record) | High | 7.1 | A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data. | Dec 12, 2023 |
| CVE-2023-5379(opens NVD record) | High | 7.5 | A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS). | Dec 12, 2023 |
| CVE-2023-34064(opens NVD record) | Medium | 4.6 | Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information. | Dec 12, 2023 |
| CVE-2023-36696(opens NVD record) | High | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-36391(opens NVD record) | High | 7.8 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-36020(opens NVD record) | High | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Dec 12, 2023 |
| CVE-2023-36019(opens NVD record) | Critical | 9.6 | Microsoft Power Platform Connector Spoofing Vulnerability | Dec 12, 2023 |
| CVE-2023-36012(opens NVD record) | Medium | 5.3 | DHCP Server Service Information Disclosure Vulnerability | Dec 12, 2023 |
| CVE-2023-36011(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-36010(opens NVD record) | High | 7.5 | Microsoft Defender Denial of Service Vulnerability | Dec 12, 2023 |
| CVE-2023-36009(opens NVD record) | Medium | 5.5 | Microsoft Word Information Disclosure Vulnerability | Dec 12, 2023 |
| CVE-2023-36006(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-36005(opens NVD record) | High | 7.5 | Windows Telephony Server Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-36004(opens NVD record) | High | 7.5 | Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability | Dec 12, 2023 |
| CVE-2023-36003(opens NVD record) | Medium | 6.7 | XAML Diagnostics Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-35644(opens NVD record) | High | 7.8 | Windows Sysmain Service Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-35643(opens NVD record) | High | 7.5 | DHCP Server Service Information Disclosure Vulnerability | Dec 12, 2023 |
| CVE-2023-35642(opens NVD record) | Medium | 6.5 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Dec 12, 2023 |
| CVE-2023-35641(opens NVD record) | High | 8.8 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-35639(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-35638(opens NVD record) | High | 7.5 | DHCP Server Service Denial of Service Vulnerability | Dec 12, 2023 |
| CVE-2023-35636(opens NVD record) | Medium | 6.5 | Microsoft Outlook Information Disclosure Vulnerability | Dec 12, 2023 |
| CVE-2023-35635(opens NVD record) | Medium | 5.5 | Windows Kernel Denial of Service Vulnerability | Dec 12, 2023 |
| CVE-2023-35634(opens NVD record) | High | 8.0 | Windows Bluetooth Driver Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-35633(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-35632(opens NVD record) | High | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-35631(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | Dec 12, 2023 |
| CVE-2023-35630(opens NVD record) | High | 8.8 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-35629(opens NVD record) | Medium | 6.8 | Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | Dec 12, 2023 |
| CVE-2023-35628(opens NVD record) | High | 8.1 | Windows MSHTML Platform Remote Code Execution Vulnerability | Dec 12, 2023 |