Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,427 matching · page 1028/1269Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-45283(opens NVD record) | High | 7.5 | The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored. | Nov 9, 2023 |
| CVE-2023-40055(opens NVD record) | High | 8.0 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | Nov 9, 2023 |
| CVE-2023-40054(opens NVD record) | High | 8.0 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | Nov 9, 2023 |
| CVE-2023-37790(opens NVD record) | Medium | 5.4 | Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function. | Nov 9, 2023 |
| CVE-2023-4891(opens NVD record) | Medium | 5.5 | A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. | Nov 8, 2023 |
| CVE-2023-47113(opens NVD record) | High | 7.3 | BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerable to a DLL Hijacking vulnerability. By placing a DLL in the Folder c:\DLLs, an attacker can run arbitrary code on every execution of BleachBit for Windows. This issue has been patched in version 4.5.0. | Nov 8, 2023 |
| CVE-2023-0392(opens NVD record) | Medium | 6.7 | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution. | Nov 8, 2023 |
| CVE-2023-3282(opens NVD record) | Medium | 6.4 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine. | Nov 8, 2023 |
| CVE-2023-5913(opens NVD record) | High | 8.2 | Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1. | Nov 8, 2023 |
| CVE-2023-46759(opens NVD record) | High | 7.5 | Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-46758(opens NVD record) | High | 7.5 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | Nov 8, 2023 |
| CVE-2023-46757(opens NVD record) | High | 7.5 | The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality. | Nov 8, 2023 |
| CVE-2023-46756(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. | Nov 8, 2023 |
| CVE-2023-46774(opens NVD record) | High | 7.5 | Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability. | Nov 8, 2023 |
| CVE-2023-46772(opens NVD record) | High | 7.5 | Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vulnerability may cause errors in reading file data. | Nov 8, 2023 |
| CVE-2023-46767(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46766(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46765(opens NVD record) | High | 7.5 | Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability. | Nov 8, 2023 |
| CVE-2023-46764(opens NVD record) | Medium | 5.3 | Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously. | Nov 8, 2023 |
| CVE-2023-46763(opens NVD record) | Medium | 5.3 | Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously. | Nov 8, 2023 |
| CVE-2023-46762(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46761(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46760(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46755(opens NVD record) | Medium | 5.3 | Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart. | Nov 8, 2023 |
| CVE-2022-48613(opens NVD record) | Medium | 5.9 | Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed. | Nov 8, 2023 |
| CVE-2023-46771(opens NVD record) | High | 7.5 | Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-44098(opens NVD record) | High | 7.5 | Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-44115(opens NVD record) | High | 7.5 | Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-5801(opens NVD record) | Critical | 9.1 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality. | Nov 8, 2023 |
| CVE-2023-46770(opens NVD record) | High | 7.5 | Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones. | Nov 8, 2023 |
| CVE-2023-46769(opens NVD record) | High | 7.5 | Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability. | Nov 8, 2023 |
| CVE-2023-46768(opens NVD record) | High | 7.5 | Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Nov 8, 2023 |
| CVE-2023-4061(opens NVD record) | Medium | 6.5 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. | Nov 8, 2023 |
| CVE-2023-4956(opens NVD record) | Medium | 6.5 | A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to trick an administrator user into clicking on buttons on the config-editor panel, possibly reconfiguring some parts of the Quay instance. | Nov 7, 2023 |
| CVE-2023-42659(opens NVD record) | Critical | 9.1 | In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application. | Nov 7, 2023 |
| CVE-2023-41425(opens NVD record) | Medium | 6.1 | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component. | Nov 7, 2023 |
| CVE-2023-36409(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Nov 7, 2023 |
| CVE-2023-36769(opens NVD record) | Medium | 4.6 | Microsoft OneNote Spoofing Vulnerability | Nov 6, 2023 |
| CVE-2023-4535(opens NVD record) | Medium | 4.5 | An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security. | Nov 6, 2023 |
| CVE-2023-40661(opens NVD record) | Medium | 5.4 | Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment. | Nov 6, 2023 |
| CVE-2023-40660(opens NVD record) | Medium | 6.6 | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness. | Nov 6, 2023 |
| CVE-2023-4910(opens NVD record) | Medium | 5.5 | A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. | Nov 6, 2023 |
| CVE-2023-5090(opens NVD record) | Medium | 6.0 | A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition. | Nov 6, 2023 |
| CVE-2023-4996(opens NVD record) | Medium | 6.6 | Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. | Nov 6, 2023 |
| CVE-2023-42669(opens NVD record) | Medium | 6.5 | A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task, allowing calls to the "rpcecho" server to be blocked for a specified time, causing service disruptions. This disruption is triggered by a "sleep()" call in the "dcesrv_echo_TestSleep()" function under specific conditions. Authenticated users or attackers can exploit this vulnerability to make calls to the "rpcecho" server, requesting it to block for a specified duration, effectively disrupting most services and leading to a complete denial of service on the AD DC. The DoS affects all other services as "rpcecho" runs in the main RPC task. | Nov 6, 2023 |
| CVE-2023-45189(opens NVD record) | Medium | 6.5 | A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752. | Nov 3, 2023 |
| CVE-2023-41726(opens NVD record) | High | 7.8 | Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2023-41725(opens NVD record) | High | 7.8 | Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2022-44569(opens NVD record) | High | 7.8 | A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. | Nov 3, 2023 |
| CVE-2022-43555(opens NVD record) | High | 7.8 | Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability | Nov 3, 2023 |