Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,151 matching · page 1019/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-44340(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Nov 16, 2023 |
| CVE-2023-44339(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Nov 16, 2023 |
| CVE-2023-44338(opens NVD record) | High | 7.8 | Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Nov 16, 2023 |
| CVE-2023-44337(opens NVD record) | High | 7.8 | Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Nov 16, 2023 |
| CVE-2023-44336(opens NVD record) | High | 7.8 | Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Nov 16, 2023 |
| CVE-2023-44292(opens NVD record) | Medium | 6.7 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | Nov 16, 2023 |
| CVE-2023-44282(opens NVD record) | Medium | 6.7 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | Nov 16, 2023 |
| CVE-2023-39259(opens NVD record) | High | 7.3 | Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system. | Nov 16, 2023 |
| CVE-2023-39246(opens NVD record) | Medium | 4.6 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a restricted directory, leading to Privilege Escalation | Nov 16, 2023 |
| CVE-2023-32469(opens NVD record) | High | 7.5 | Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user with admin privileges could potentially exploit this vulnerability to perform arbitrary code execution. | Nov 16, 2023 |
| CVE-2023-44296(opens NVD record) | High | 8.4 | Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data. Successful exploitation may result in the compromise of confidential user information. | Nov 16, 2023 |
| CVE-2023-47264(opens NVD record) | High | 7.5 | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, WithSecure Linux Security 64 12.0, WithSecure Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 15 and later. | Nov 16, 2023 |
| CVE-2023-47263(opens NVD record) | High | 7.5 | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, WithSecure Linux Security 64 12.0, WithSecure Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 15 and later. | Nov 16, 2023 |
| CVE-2023-6105(opens NVD record) | Medium | 5.5 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database. | Nov 15, 2023 |
| CVE-2023-34062(opens NVD record) | High | 7.5 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources. | Nov 15, 2023 |
| CVE-2023-41718(opens NVD record) | High | 7.8 | When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. | Nov 15, 2023 |
| CVE-2023-39337(opens NVD record) | Critical | 9.1 | A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk, potentially exposing confidential data and system integrity. | Nov 15, 2023 |
| CVE-2023-39335(opens NVD record) | Critical | 9.8 | A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources. | Nov 15, 2023 |
| CVE-2023-38544(opens NVD record) | Medium | 5.5 | A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system. | Nov 15, 2023 |
| CVE-2023-38543(opens NVD record) | High | 7.8 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine. | Nov 15, 2023 |
| CVE-2023-38043(opens NVD record) | High | 7.8 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system. | Nov 15, 2023 |
| CVE-2023-35080(opens NVD record) | High | 7.8 | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure. | Nov 15, 2023 |
| CVE-2023-5189(opens NVD record) | Medium | 6.3 | A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten. | Nov 14, 2023 |
| CVE-2023-45627(opens NVD record) | Medium | 4.3 | An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45626(opens NVD record) | Medium | 5.5 | An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles. | Nov 14, 2023 |
| CVE-2023-45625(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45624(opens NVD record) | High | 7.5 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45623(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45622(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45621(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45620(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45619(opens NVD record) | High | 8.2 | There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45618(opens NVD record) | High | 8.2 | There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45617(opens NVD record) | High | 8.2 | There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45616(opens NVD record) | Critical | 9.8 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45615(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45614(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-36558(opens NVD record) | Medium | 6.2 | ASP.NET Core Security Feature Bypass Vulnerability | Nov 14, 2023 |
| CVE-2023-36038(opens NVD record) | High | 8.2 | ASP.NET Core Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-5528(opens NVD record) | High | 7.2 | A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes. | Nov 14, 2023 |
| CVE-2023-36437(opens NVD record) | High | 8.8 | Azure DevOps Server Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36049(opens NVD record) | High | 7.6 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36007(opens NVD record) | High | 7.6 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-34060(opens NVD record) | Critical | 9.8 | VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5). | Nov 14, 2023 |
| CVE-2023-40719(opens NVD record) | Medium | 4.1 | A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials. | Nov 14, 2023 |
| CVE-2023-39412(opens NVD record) | Medium | 5.4 | Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-39411(opens NVD record) | Medium | 5.0 | Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-39228(opens NVD record) | Medium | 5.3 | Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | Nov 14, 2023 |
| CVE-2023-39221(opens NVD record) | Medium | 5.4 | Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-38570(opens NVD record) | Medium | 5.3 | Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |