Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,427 matching · page 1027/1269Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-36396(opens NVD record) | High | 7.8 | Windows Compressed Folder Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36395(opens NVD record) | High | 7.5 | Windows Deployment Services Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-36394(opens NVD record) | High | 7.0 | Windows Search Service Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36393(opens NVD record) | High | 7.8 | Windows User Interface Application Core Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36392(opens NVD record) | High | 7.5 | DHCP Server Service Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-36052(opens NVD record) | High | 8.6 | Azure CLI REST Command Information Disclosure Vulnerability | Nov 14, 2023 |
| CVE-2023-36050(opens NVD record) | High | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36047(opens NVD record) | High | 7.8 | Windows Authentication Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36046(opens NVD record) | High | 7.1 | Windows Authentication Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-36045(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36043(opens NVD record) | Medium | 6.5 | Open Management Infrastructure Information Disclosure Vulnerability | Nov 14, 2023 |
| CVE-2023-36042(opens NVD record) | Medium | 6.2 | Visual Studio Denial of Service Vulnerability | Nov 14, 2023 |
| CVE-2023-36041(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36039(opens NVD record) | High | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36037(opens NVD record) | High | 7.8 | Microsoft Excel Security Feature Bypass Vulnerability | Nov 14, 2023 |
| CVE-2023-36036(opens NVD record) | High | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36035(opens NVD record) | High | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36033(opens NVD record) | High | 7.8 | Windows DWM Core Library Elevation of Privilege Vulnerability | Nov 14, 2023 |
| CVE-2023-36031(opens NVD record) | High | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Nov 14, 2023 |
| CVE-2023-36030(opens NVD record) | Medium | 6.1 | Microsoft Dynamics 365 Sales Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36028(opens NVD record) | Critical | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Nov 14, 2023 |
| CVE-2023-36025(opens NVD record) | High | 8.8 | Windows SmartScreen Security Feature Bypass Vulnerability | Nov 14, 2023 |
| CVE-2023-36021(opens NVD record) | High | 8.0 | Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | Nov 14, 2023 |
| CVE-2023-36018(opens NVD record) | High | 7.8 | Visual Studio Code Jupyter Extension Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36017(opens NVD record) | High | 8.8 | Windows Scripting Engine Memory Corruption Vulnerability | Nov 14, 2023 |
| CVE-2023-36016(opens NVD record) | Medium | 6.2 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Nov 14, 2023 |
| CVE-2023-34991(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request. | Nov 14, 2023 |
| CVE-2023-33304(opens NVD record) | Medium | 4.4 | A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials. | Nov 14, 2023 |
| CVE-2023-28002(opens NVD record) | Medium | 6.4 | An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place. | Nov 14, 2023 |
| CVE-2023-26205(opens NVD record) | High | 8.1 | An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script. | Nov 14, 2023 |
| CVE-2023-43902(opens NVD record) | Critical | 9.8 | Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token. | Nov 14, 2023 |
| CVE-2023-43901(opens NVD record) | High | 7.5 | Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user. | Nov 14, 2023 |
| CVE-2023-43900(opens NVD record) | Medium | 6.5 | Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters. | Nov 14, 2023 |
| CVE-2023-6006(opens NVD record) | High | 7.8 | This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system. This vulnerability does not apply to PaperCut NG installs that have Print Archiving enabled and configured as per the recommended set up procedure. This specific flaw exists within the pc-pdl-to-image process. The process loads an executable from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM Note: This CVE has been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server. | Nov 14, 2023 |
| CVE-2023-38364(opens NVD record) | Medium | 6.1 | IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260821. | Nov 13, 2023 |
| CVE-2023-38363(opens NVD record) | Medium | 4.3 | IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 260818. | Nov 13, 2023 |
| CVE-2023-28134(opens NVD record) | High | 7.8 | Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Nov 12, 2023 |
| CVE-2023-43057(opens NVD record) | Medium | 4.6 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267484. | Nov 11, 2023 |
| CVE-2023-46850(opens NVD record) | Critical | 9.8 | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer. | Nov 11, 2023 |
| CVE-2023-46849(opens NVD record) | High | 7.5 | Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service. | Nov 11, 2023 |
| CVE-2023-36027(opens NVD record) | High | 7.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Nov 10, 2023 |
| CVE-2023-47246(opens NVD record) | Critical | 9.8 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | Nov 10, 2023 |
| CVE-2023-45167(opens NVD record) | Medium | 6.2 | IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965. | Nov 10, 2023 |
| CVE-2023-36024(opens NVD record) | High | 7.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Nov 10, 2023 |
| CVE-2023-36014(opens NVD record) | High | 7.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Nov 10, 2023 |
| CVE-2023-5547(opens NVD record) | Low | 3.3 | The course upload preview contained an XSS risk for users uploading unsafe data. | Nov 9, 2023 |
| CVE-2023-5546(opens NVD record) | Medium | 4.3 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. | Nov 9, 2023 |
| CVE-2023-5544(opens NVD record) | Medium | 6.5 | Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. | Nov 9, 2023 |
| CVE-2023-39198(opens NVD record) | High | 7.5 | A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of service or privilege escalation. | Nov 9, 2023 |
| CVE-2023-45284(opens NVD record) | Medium | 5.3 | On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local. | Nov 9, 2023 |