Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
65,251 matching · page 1042/1306Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-34381(opens NVD record) | Critical | 9.1 | Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity. | Feb 2, 2024 |
| CVE-2021-21575(opens NVD record) | Medium | 5.9 | Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. | Feb 2, 2024 |
| CVE-2020-29504(opens NVD record) | High | 7.4 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability. | Feb 2, 2024 |
| CVE-2023-38273(opens NVD record) | High | 7.5 | IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733. | Feb 2, 2024 |
| CVE-2023-47142(opens NVD record) | High | 7.5 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. | Feb 2, 2024 |
| CVE-2024-0269(opens NVD record) | High | 8.3 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271. | Feb 2, 2024 |
| CVE-2024-0253(opens NVD record) | High | 8.3 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data. | Feb 2, 2024 |
| CVE-2023-47148(opens NVD record) | Medium | 5.3 | IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599. | Feb 2, 2024 |
| CVE-2023-47144(opens NVD record) | Medium | 6.1 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271. | Feb 2, 2024 |
| CVE-2023-47143(opens NVD record) | Critical | 10.0 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270. | Feb 2, 2024 |
| CVE-2023-51072(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators. | Feb 2, 2024 |
| CVE-2020-24682(opens NVD record) | High | 7.2 | Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP; NET/PVI: from 4.0 through 4.6, from 4.7.0 before 4.7.7, from 4.8.0 before 4.8.6, from 4.9.0 before 4.9.4. | Feb 2, 2024 |
| CVE-2020-24681(opens NVD record) | High | 8.2 | Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP. | Feb 2, 2024 |
| CVE-2024-24482(opens NVD record) | Critical | 9.8 | Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. | Feb 2, 2024 |
| CVE-2023-38263(opens NVD record) | Medium | 6.5 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577. | Feb 2, 2024 |
| CVE-2023-38020(opens NVD record) | Medium | 4.3 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576. | Feb 2, 2024 |
| CVE-2023-38019(opens NVD record) | High | 8.1 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575. | Feb 2, 2024 |
| CVE-2022-40744(opens NVD record) | Medium | 4.8 | IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441. | Feb 2, 2024 |
| CVE-2024-22320(opens NVD record) | Critical | 9.8 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146. | Feb 2, 2024 |
| CVE-2024-22319(opens NVD record) | High | 8.1 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. | Feb 2, 2024 |
| CVE-2023-46159(opens NVD record) | Low | 2.6 | IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906. | Feb 2, 2024 |
| CVE-2024-22903(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. | Feb 2, 2024 |
| CVE-2024-22902(opens NVD record) | Critical | 9.8 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. | Feb 2, 2024 |
| CVE-2024-22901(opens NVD record) | Critical | 9.8 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. | Feb 2, 2024 |
| CVE-2024-22900(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. | Feb 2, 2024 |
| CVE-2024-22899(opens NVD record) | High | 8.8 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. | Feb 2, 2024 |
| CVE-2023-50962(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004. | Feb 2, 2024 |
| CVE-2023-50941(opens NVD record) | Medium | 6.3 | IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131. | Feb 2, 2024 |
| CVE-2023-50938(opens NVD record) | Medium | 6.5 | IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 275128. | Feb 2, 2024 |
| CVE-2023-50935(opens NVD record) | Medium | 6.5 | IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115. | Feb 2, 2024 |
| CVE-2023-50934(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114. | Feb 2, 2024 |
| CVE-2023-50328(opens NVD record) | Low | 3.7 | IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110. | Feb 2, 2024 |
| CVE-2023-48793(opens NVD record) | Critical | 9.8 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | Feb 2, 2024 |
| CVE-2023-48792(opens NVD record) | Critical | 9.8 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | Feb 2, 2024 |
| CVE-2023-46344(opens NVD record) | Medium | 5.4 | A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base. | Feb 2, 2024 |
| CVE-2023-32333(opens NVD record) | Medium | 6.5 | IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073. | Feb 2, 2024 |
| CVE-2024-21399(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Feb 2, 2024 |
| CVE-2023-50940(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130. | Feb 2, 2024 |
| CVE-2023-50937(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117. | Feb 2, 2024 |
| CVE-2023-50936(opens NVD record) | Medium | 6.3 | IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116. | Feb 2, 2024 |
| CVE-2023-50933(opens NVD record) | Medium | 6.1 | IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113. | Feb 2, 2024 |
| CVE-2023-50327(opens NVD record) | Medium | 5.3 | IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: 275109. | Feb 2, 2024 |
| CVE-2023-50326(opens NVD record) | High | 7.5 | IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107. | Feb 2, 2024 |
| CVE-2023-50939(opens NVD record) | Medium | 5.9 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129. | Feb 2, 2024 |
| CVE-2023-36496(opens NVD record) | High | 7.7 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | Feb 1, 2024 |
| CVE-2024-22449(opens NVD record) | Medium | 6.6 | Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access. | Feb 1, 2024 |
| CVE-2024-22430(opens NVD record) | Medium | 5.5 | Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service. | Feb 1, 2024 |
| CVE-2024-21626(opens NVD record) | High | 8.6 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. | Jan 31, 2024 |
| CVE-2024-21893(opens NVD record) | High | 8.2 | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. | Jan 31, 2024 |
| CVE-2024-21888(opens NVD record) | High | 8.8 | A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. | Jan 31, 2024 |