Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,427 matching · page 1029/1269Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-43554(opens NVD record) | High | 7.8 | Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2023-5088(opens NVD record) | Medium | 6.4 | A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot. | Nov 3, 2023 |
| CVE-2023-3961(opens NVD record) | Critical | 9.1 | A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes. | Nov 3, 2023 |
| CVE-2023-4769(opens NVD record) | Medium | 6.6 | A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests. | Nov 3, 2023 |
| CVE-2023-4768(opens NVD record) | Medium | 6.1 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. | Nov 3, 2023 |
| CVE-2023-4767(opens NVD record) | Medium | 6.1 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. | Nov 3, 2023 |
| CVE-2023-1476(opens NVD record) | High | 7.0 | A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system. | Nov 3, 2023 |
| CVE-2023-5824(opens NVD record) | High | 7.5 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service. | Nov 3, 2023 |
| CVE-2023-4091(opens NVD record) | Medium | 6.5 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions. | Nov 3, 2023 |
| CVE-2023-46848(opens NVD record) | High | 8.6 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. | Nov 3, 2023 |
| CVE-2023-46847(opens NVD record) | High | 8.6 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. | Nov 3, 2023 |
| CVE-2023-46846(opens NVD record) | Critical | 9.3 | SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. | Nov 3, 2023 |
| CVE-2023-41355(opens NVD record) | Critical | 9.8 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking. | Nov 3, 2023 |
| CVE-2023-41354(opens NVD record) | Medium | 4.0 | Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor. | Nov 3, 2023 |
| CVE-2023-41353(opens NVD record) | High | 8.8 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service. | Nov 3, 2023 |
| CVE-2023-41352(opens NVD record) | High | 7.2 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services. | Nov 3, 2023 |
| CVE-2023-41351(opens NVD record) | Critical | 9.8 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service. | Nov 3, 2023 |
| CVE-2023-41350(opens NVD record) | High | 7.5 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks. | Nov 3, 2023 |
| CVE-2023-31102(opens NVD record) | High | 7.8 | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | Nov 3, 2023 |
| CVE-2023-35896(opens NVD record) | Medium | 5.4 | IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247. | Nov 3, 2023 |
| CVE-2023-46176(opens NVD record) | Medium | 6.7 | IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535. | Nov 3, 2023 |
| CVE-2023-36034(opens NVD record) | High | 7.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Nov 3, 2023 |
| CVE-2023-36029(opens NVD record) | Medium | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Nov 3, 2023 |
| CVE-2023-36022(opens NVD record) | Medium | 6.6 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Nov 3, 2023 |
| CVE-2023-43018(opens NVD record) | Medium | 5.9 | IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163. | Nov 3, 2023 |
| CVE-2023-42029(opens NVD record) | Medium | 4.8 | IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 266059. | Nov 3, 2023 |
| CVE-2023-42027(opens NVD record) | Medium | 4.3 | IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057. | Nov 3, 2023 |
| CVE-2023-46958(opens NVD record) | Critical | 9.8 | An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file. | Nov 2, 2023 |
| CVE-2023-31027(opens NVD record) | High | 8.2 | NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges. | Nov 2, 2023 |
| CVE-2023-31026(opens NVD record) | Medium | 6.0 | NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service. | Nov 2, 2023 |
| CVE-2023-31023(opens NVD record) | Medium | 5.5 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service. | Nov 2, 2023 |
| CVE-2023-31022(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service. | Nov 2, 2023 |
| CVE-2023-31021(opens NVD record) | Medium | 5.5 | NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service. | Nov 2, 2023 |
| CVE-2023-31020(opens NVD record) | Medium | 6.1 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering. | Nov 2, 2023 |
| CVE-2023-31019(opens NVD record) | High | 7.8 | NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context. | Nov 2, 2023 |
| CVE-2023-31018(opens NVD record) | Medium | 6.5 | NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service. | Nov 2, 2023 |
| CVE-2023-31017(opens NVD record) | High | 7.8 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | Nov 2, 2023 |
| CVE-2023-31016(opens NVD record) | High | 7.3 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | Nov 2, 2023 |
| CVE-2023-38473(opens NVD record) | Medium | 6.2 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. | Nov 2, 2023 |
| CVE-2022-4900(opens NVD record) | Medium | 6.2 | A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. | Nov 2, 2023 |
| CVE-2023-38472(opens NVD record) | Medium | 6.2 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. | Nov 2, 2023 |
| CVE-2023-38471(opens NVD record) | Medium | 6.2 | A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. | Nov 2, 2023 |
| CVE-2023-38470(opens NVD record) | Medium | 6.2 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. | Nov 2, 2023 |
| CVE-2023-38469(opens NVD record) | Medium | 6.2 | A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. | Nov 2, 2023 |
| CVE-2023-43336(opens NVD record) | High | 8.8 | Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101. | Nov 2, 2023 |
| CVE-2023-3164(opens NVD record) | Medium | 5.5 | A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file. | Nov 2, 2023 |
| CVE-2023-43087(opens NVD record) | Medium | 4.3 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | Nov 2, 2023 |
| CVE-2023-43076(opens NVD record) | Medium | 6.5 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. | Nov 2, 2023 |
| CVE-2023-5408(opens NVD record) | High | 7.2 | A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster. | Nov 2, 2023 |
| CVE-2023-1192(opens NVD record) | Medium | 6.5 | A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service. | Nov 1, 2023 |