Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
65,227 matching · page 1049/1305Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-46474(opens NVD record) | High | 7.2 | File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file. | Jan 11, 2024 |
| CVE-2024-20675(opens NVD record) | Medium | 6.3 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Jan 11, 2024 |
| CVE-2023-50128(opens NVD record) | Medium | 5.3 | The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker being able to conduct replay attacks to bring the alarm system to a disarmed state. | Jan 11, 2024 |
| CVE-2023-51751(opens NVD record) | Medium | 6.8 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | Jan 11, 2024 |
| CVE-2023-51750(opens NVD record) | Medium | 4.6 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules." | Jan 11, 2024 |
| CVE-2023-7070(opens NVD record) | Medium | 6.4 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Jan 11, 2024 |
| CVE-2024-0252(opens NVD record) | High | 8.8 | ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability. | Jan 11, 2024 |
| CVE-2023-45171(opens NVD record) | Medium | 6.2 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969. | Jan 11, 2024 |
| CVE-2023-45169(opens NVD record) | Medium | 6.2 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967. | Jan 11, 2024 |
| CVE-2023-38267(opens NVD record) | Medium | 6.2 | IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584. | Jan 11, 2024 |
| CVE-2023-31003(opens NVD record) | High | 8.4 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658. | Jan 11, 2024 |
| CVE-2023-31001(opens NVD record) | Medium | 5.1 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653. | Jan 11, 2024 |
| CVE-2023-45175(opens NVD record) | Medium | 6.2 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 267973. | Jan 11, 2024 |
| CVE-2023-45173(opens NVD record) | Medium | 6.2 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 267971. | Jan 11, 2024 |
| CVE-2024-21638(opens NVD record) | Critical | 9.1 | Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal used is only assigned the Reader role at the root Management Group level. Until recently, the solution lacked the validation of the passed in authentication token which may result in attacker impersonating any privileged user to access data stored within the IPAM instance and subsequently from Azure, causing an elevation of privilege. This vulnerability has been patched in version 3.0.0. | Jan 10, 2024 |
| CVE-2023-31488(opens NVD record) | Critical | 9.8 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | Jan 10, 2024 |
| CVE-2023-48783(opens NVD record) | Medium | 5.4 | An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests. | Jan 10, 2024 |
| CVE-2023-46712(opens NVD record) | High | 7.2 | A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. | Jan 10, 2024 |
| CVE-2023-44250(opens NVD record) | High | 8.8 | An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests. | Jan 10, 2024 |
| CVE-2023-37934(opens NVD record) | Medium | 4.3 | An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency. | Jan 10, 2024 |
| CVE-2023-37932(opens NVD record) | Medium | 6.5 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests | Jan 10, 2024 |
| CVE-2024-20715(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20714(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20713(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20712(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20711(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2024-20710(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jan 10, 2024 |
| CVE-2023-5455(opens NVD record) | Medium | 6.5 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | Jan 10, 2024 |
| CVE-2024-0310(opens NVD record) | Medium | 6.1 | A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration. | Jan 10, 2024 |
| CVE-2024-21643(opens NVD record) | High | 7.1 | IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for the `SignedHttpRequest`protocol. This raises the possibility to make any remote or local `HTTP GET` request. The vulnerability has been fixed in Microsoft.IdentityModel.Protocols.SignedHttpRequest. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher. | Jan 10, 2024 |
| CVE-2023-6476(opens NVD record) | Medium | 6.5 | A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node. | Jan 9, 2024 |
| CVE-2024-21319(opens NVD record) | Medium | 6.8 | Microsoft Identity Denial of service vulnerability | Jan 9, 2024 |
| CVE-2024-21325(opens NVD record) | High | 7.8 | Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21320(opens NVD record) | Medium | 6.5 | Windows Themes Spoofing Vulnerability | Jan 9, 2024 |
| CVE-2024-21318(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21316(opens NVD record) | Medium | 6.1 | Windows Server Key Distribution Service Security Feature Bypass | Jan 9, 2024 |
| CVE-2024-21314(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21313(opens NVD record) | Medium | 5.3 | Windows TCP/IP Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21312(opens NVD record) | High | 7.5 | .NET Framework Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-21311(opens NVD record) | Medium | 5.5 | Windows Cryptographic Services Information Disclosure Vulnerability | Jan 9, 2024 |
| CVE-2024-21310(opens NVD record) | High | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-21309(opens NVD record) | High | 7.8 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-21307(opens NVD record) | High | 7.5 | Remote Desktop Client Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-21306(opens NVD record) | Medium | 5.7 | Microsoft Bluetooth Driver Spoofing Vulnerability | Jan 9, 2024 |
| CVE-2024-21305(opens NVD record) | Medium | 4.4 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | Jan 9, 2024 |
| CVE-2024-20700(opens NVD record) | High | 7.5 | Windows Hyper-V Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20699(opens NVD record) | Medium | 5.5 | Windows Hyper-V Denial of Service Vulnerability | Jan 9, 2024 |
| CVE-2024-20698(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jan 9, 2024 |
| CVE-2024-20697(opens NVD record) | High | 7.3 | Windows libarchive Remote Code Execution Vulnerability | Jan 9, 2024 |
| CVE-2024-20696(opens NVD record) | High | 7.3 | Windows libarchive Remote Code Execution Vulnerability | Jan 9, 2024 |