Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
65,660 matching · page 1073/1314Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-36018(opens NVD record) | High | 7.8 | Visual Studio Code Jupyter Extension Spoofing Vulnerability | Nov 14, 2023 |
| CVE-2023-36017(opens NVD record) | High | 8.8 | Windows Scripting Engine Memory Corruption Vulnerability | Nov 14, 2023 |
| CVE-2023-36016(opens NVD record) | Medium | 6.2 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Nov 14, 2023 |
| CVE-2023-34991(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request. | Nov 14, 2023 |
| CVE-2023-33304(opens NVD record) | Medium | 4.4 | A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials. | Nov 14, 2023 |
| CVE-2023-28002(opens NVD record) | Medium | 6.4 | An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place. | Nov 14, 2023 |
| CVE-2023-26205(opens NVD record) | High | 8.1 | An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script. | Nov 14, 2023 |
| CVE-2023-43902(opens NVD record) | Critical | 9.8 | Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token. | Nov 14, 2023 |
| CVE-2023-43901(opens NVD record) | High | 7.5 | Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user. | Nov 14, 2023 |
| CVE-2023-43900(opens NVD record) | Medium | 6.5 | Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters. | Nov 14, 2023 |
| CVE-2023-6006(opens NVD record) | High | 7.8 | This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system. This vulnerability does not apply to PaperCut NG installs that have Print Archiving enabled and configured as per the recommended set up procedure. This specific flaw exists within the pc-pdl-to-image process. The process loads an executable from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM Note: This CVE has been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server. | Nov 14, 2023 |
| CVE-2023-38364(opens NVD record) | Medium | 6.1 | IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260821. | Nov 13, 2023 |
| CVE-2023-38363(opens NVD record) | Medium | 4.3 | IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 260818. | Nov 13, 2023 |
| CVE-2023-28134(opens NVD record) | High | 7.8 | Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Nov 12, 2023 |
| CVE-2023-43057(opens NVD record) | Medium | 4.6 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267484. | Nov 11, 2023 |
| CVE-2023-46850(opens NVD record) | Critical | 9.8 | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer. | Nov 11, 2023 |
| CVE-2023-46849(opens NVD record) | High | 7.5 | Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service. | Nov 11, 2023 |
| CVE-2023-36027(opens NVD record) | High | 7.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Nov 10, 2023 |
| CVE-2023-47246(opens NVD record) | Critical | 9.8 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | Nov 10, 2023 |
| CVE-2023-45167(opens NVD record) | Medium | 6.2 | IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965. | Nov 10, 2023 |
| CVE-2023-36024(opens NVD record) | High | 7.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Nov 10, 2023 |
| CVE-2023-36014(opens NVD record) | High | 7.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Nov 10, 2023 |
| CVE-2023-5547(opens NVD record) | Low | 3.3 | The course upload preview contained an XSS risk for users uploading unsafe data. | Nov 9, 2023 |
| CVE-2023-5546(opens NVD record) | Medium | 4.3 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. | Nov 9, 2023 |
| CVE-2023-5544(opens NVD record) | Medium | 6.5 | Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. | Nov 9, 2023 |
| CVE-2023-39198(opens NVD record) | High | 7.5 | A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of service or privilege escalation. | Nov 9, 2023 |
| CVE-2023-45284(opens NVD record) | Medium | 5.3 | On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local. | Nov 9, 2023 |
| CVE-2023-45283(opens NVD record) | High | 7.5 | The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored. | Nov 9, 2023 |
| CVE-2023-40055(opens NVD record) | High | 8.0 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | Nov 9, 2023 |
| CVE-2023-40054(opens NVD record) | High | 8.0 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | Nov 9, 2023 |
| CVE-2023-37790(opens NVD record) | Medium | 5.4 | Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function. | Nov 9, 2023 |
| CVE-2023-4891(opens NVD record) | Medium | 5.5 | A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. | Nov 8, 2023 |
| CVE-2023-47113(opens NVD record) | High | 7.3 | BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerable to a DLL Hijacking vulnerability. By placing a DLL in the Folder c:\DLLs, an attacker can run arbitrary code on every execution of BleachBit for Windows. This issue has been patched in version 4.5.0. | Nov 8, 2023 |
| CVE-2023-0392(opens NVD record) | Medium | 6.7 | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution. | Nov 8, 2023 |
| CVE-2023-3282(opens NVD record) | Medium | 6.4 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine. | Nov 8, 2023 |
| CVE-2023-5913(opens NVD record) | High | 8.2 | Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1. | Nov 8, 2023 |
| CVE-2023-46759(opens NVD record) | High | 7.5 | Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-46758(opens NVD record) | High | 7.5 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | Nov 8, 2023 |
| CVE-2023-46757(opens NVD record) | High | 7.5 | The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality. | Nov 8, 2023 |
| CVE-2023-46756(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. | Nov 8, 2023 |
| CVE-2023-46774(opens NVD record) | High | 7.5 | Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability. | Nov 8, 2023 |
| CVE-2023-46772(opens NVD record) | High | 7.5 | Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vulnerability may cause errors in reading file data. | Nov 8, 2023 |
| CVE-2023-46767(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46766(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46765(opens NVD record) | High | 7.5 | Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability. | Nov 8, 2023 |
| CVE-2023-46764(opens NVD record) | Medium | 5.3 | Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously. | Nov 8, 2023 |
| CVE-2023-46763(opens NVD record) | Medium | 5.3 | Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously. | Nov 8, 2023 |
| CVE-2023-46762(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46761(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |
| CVE-2023-46760(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | Nov 8, 2023 |