Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,427 matching · page 1025/1269Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-45626(opens NVD record) | Medium | 5.5 | An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles. | Nov 14, 2023 |
| CVE-2023-45625(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45624(opens NVD record) | High | 7.5 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45623(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45622(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45621(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45620(opens NVD record) | High | 7.5 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | Nov 14, 2023 |
| CVE-2023-45619(opens NVD record) | High | 8.2 | There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45618(opens NVD record) | High | 8.2 | There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45617(opens NVD record) | High | 8.2 | There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. | Nov 14, 2023 |
| CVE-2023-45616(opens NVD record) | Critical | 9.8 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45615(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-45614(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | Nov 14, 2023 |
| CVE-2023-36558(opens NVD record) | Medium | 6.2 | ASP.NET Core Security Feature Bypass Vulnerability | Nov 14, 2023 |
| CVE-2023-36038(opens NVD record) | High | 8.2 | ASP.NET Core Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-5528(opens NVD record) | High | 7.2 | A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes. | Nov 14, 2023 |
| CVE-2023-36437(opens NVD record) | High | 8.8 | Azure DevOps Server Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36049(opens NVD record) | High | 7.6 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36007(opens NVD record) | High | 7.6 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-34060(opens NVD record) | Critical | 9.8 | VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5). | Nov 14, 2023 |
| CVE-2023-40719(opens NVD record) | Medium | 4.1 | A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials. | Nov 14, 2023 |
| CVE-2023-39412(opens NVD record) | Medium | 5.4 | Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-39411(opens NVD record) | Medium | 5.0 | Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-39228(opens NVD record) | Medium | 5.3 | Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | Nov 14, 2023 |
| CVE-2023-39221(opens NVD record) | Medium | 5.4 | Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-38570(opens NVD record) | Medium | 5.3 | Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-38131(opens NVD record) | Medium | 6.5 | Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | Nov 14, 2023 |
| CVE-2023-36860(opens NVD record) | High | 7.1 | Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-29177(opens NVD record) | Medium | 6.7 | Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests. | Nov 14, 2023 |
| CVE-2023-29165(opens NVD record) | Medium | 6.7 | Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-28741(opens NVD record) | High | 7.9 | Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-28740(opens NVD record) | Medium | 6.7 | Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-28737(opens NVD record) | High | 8.8 | Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-28723(opens NVD record) | Low | 3.3 | Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable information disclosure via local access. | Nov 14, 2023 |
| CVE-2023-28404(opens NVD record) | Low | 3.8 | Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access. | Nov 14, 2023 |
| CVE-2023-28401(opens NVD record) | Medium | 5.7 | Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-28397(opens NVD record) | High | 7.8 | Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access. | Nov 14, 2023 |
| CVE-2023-28378(opens NVD record) | Medium | 6.7 | Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-27305(opens NVD record) | Medium | 6.7 | Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | Nov 14, 2023 |
| CVE-2023-26589(opens NVD record) | Medium | 6.5 | Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-25952(opens NVD record) | Medium | 6.1 | Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-25949(opens NVD record) | Medium | 5.5 | Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-25603(opens NVD record) | Medium | 5.4 | A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests. | Nov 14, 2023 |
| CVE-2023-25071(opens NVD record) | Medium | 5.6 | NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-23583(opens NVD record) | High | 8.8 | Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access. | Nov 14, 2023 |
| CVE-2023-22663(opens NVD record) | Medium | 5.9 | Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-22448(opens NVD record) | Medium | 5.9 | Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access. | Nov 14, 2023 |
| CVE-2023-22337(opens NVD record) | High | 7.5 | Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | Nov 14, 2023 |
| CVE-2023-22310(opens NVD record) | Medium | 6.5 | Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |
| CVE-2023-22305(opens NVD record) | Medium | 6.5 | Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 |