Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
65,660 matching · page 1074/1314Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-46755(opens NVD record) | Medium | 5.3 | Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart. | Nov 8, 2023 |
| CVE-2022-48613(opens NVD record) | Medium | 5.9 | Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed. | Nov 8, 2023 |
| CVE-2023-46771(opens NVD record) | High | 7.5 | Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-44098(opens NVD record) | High | 7.5 | Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-44115(opens NVD record) | High | 7.5 | Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Nov 8, 2023 |
| CVE-2023-5801(opens NVD record) | Critical | 9.1 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality. | Nov 8, 2023 |
| CVE-2023-46770(opens NVD record) | High | 7.5 | Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones. | Nov 8, 2023 |
| CVE-2023-46769(opens NVD record) | High | 7.5 | Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability. | Nov 8, 2023 |
| CVE-2023-46768(opens NVD record) | High | 7.5 | Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Nov 8, 2023 |
| CVE-2023-4061(opens NVD record) | Medium | 6.5 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. | Nov 8, 2023 |
| CVE-2023-4956(opens NVD record) | Medium | 6.5 | A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to trick an administrator user into clicking on buttons on the config-editor panel, possibly reconfiguring some parts of the Quay instance. | Nov 7, 2023 |
| CVE-2023-42659(opens NVD record) | Critical | 9.1 | In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application. | Nov 7, 2023 |
| CVE-2023-41425(opens NVD record) | Medium | 6.1 | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component. | Nov 7, 2023 |
| CVE-2023-36409(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Nov 7, 2023 |
| CVE-2023-36769(opens NVD record) | Medium | 4.6 | Microsoft OneNote Spoofing Vulnerability | Nov 6, 2023 |
| CVE-2023-4535(opens NVD record) | Medium | 4.5 | An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security. | Nov 6, 2023 |
| CVE-2023-40661(opens NVD record) | Medium | 5.4 | Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment. | Nov 6, 2023 |
| CVE-2023-40660(opens NVD record) | Medium | 6.6 | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness. | Nov 6, 2023 |
| CVE-2023-4910(opens NVD record) | Medium | 5.5 | A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. | Nov 6, 2023 |
| CVE-2023-5090(opens NVD record) | Medium | 6.0 | A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition. | Nov 6, 2023 |
| CVE-2023-4996(opens NVD record) | Medium | 6.6 | Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. | Nov 6, 2023 |
| CVE-2023-42669(opens NVD record) | Medium | 6.5 | A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task, allowing calls to the "rpcecho" server to be blocked for a specified time, causing service disruptions. This disruption is triggered by a "sleep()" call in the "dcesrv_echo_TestSleep()" function under specific conditions. Authenticated users or attackers can exploit this vulnerability to make calls to the "rpcecho" server, requesting it to block for a specified duration, effectively disrupting most services and leading to a complete denial of service on the AD DC. The DoS affects all other services as "rpcecho" runs in the main RPC task. | Nov 6, 2023 |
| CVE-2023-45189(opens NVD record) | Medium | 6.5 | A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752. | Nov 3, 2023 |
| CVE-2023-41726(opens NVD record) | High | 7.8 | Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2023-41725(opens NVD record) | High | 7.8 | Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2022-44569(opens NVD record) | High | 7.8 | A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. | Nov 3, 2023 |
| CVE-2022-43555(opens NVD record) | High | 7.8 | Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2022-43554(opens NVD record) | High | 7.8 | Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability | Nov 3, 2023 |
| CVE-2023-5088(opens NVD record) | Medium | 6.4 | A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot. | Nov 3, 2023 |
| CVE-2023-3961(opens NVD record) | Critical | 9.1 | A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes. | Nov 3, 2023 |
| CVE-2023-4769(opens NVD record) | Medium | 6.6 | A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests. | Nov 3, 2023 |
| CVE-2023-4768(opens NVD record) | Medium | 6.1 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. | Nov 3, 2023 |
| CVE-2023-4767(opens NVD record) | Medium | 6.1 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. | Nov 3, 2023 |
| CVE-2023-1476(opens NVD record) | High | 7.0 | A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system. | Nov 3, 2023 |
| CVE-2023-5824(opens NVD record) | High | 7.5 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service. | Nov 3, 2023 |
| CVE-2023-4091(opens NVD record) | Medium | 6.5 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions. | Nov 3, 2023 |
| CVE-2023-46848(opens NVD record) | High | 8.6 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. | Nov 3, 2023 |
| CVE-2023-46847(opens NVD record) | High | 8.6 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. | Nov 3, 2023 |
| CVE-2023-46846(opens NVD record) | Critical | 9.3 | SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. | Nov 3, 2023 |
| CVE-2023-41355(opens NVD record) | Critical | 9.8 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking. | Nov 3, 2023 |
| CVE-2023-41354(opens NVD record) | Medium | 4.0 | Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor. | Nov 3, 2023 |
| CVE-2023-41353(opens NVD record) | High | 8.8 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service. | Nov 3, 2023 |
| CVE-2023-41352(opens NVD record) | High | 7.2 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services. | Nov 3, 2023 |
| CVE-2023-41351(opens NVD record) | Critical | 9.8 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service. | Nov 3, 2023 |
| CVE-2023-41350(opens NVD record) | High | 7.5 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks. | Nov 3, 2023 |
| CVE-2023-31102(opens NVD record) | High | 7.8 | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | Nov 3, 2023 |
| CVE-2023-35896(opens NVD record) | Medium | 5.4 | IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247. | Nov 3, 2023 |
| CVE-2023-46176(opens NVD record) | Medium | 6.7 | IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535. | Nov 3, 2023 |
| CVE-2023-36034(opens NVD record) | High | 7.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Nov 3, 2023 |
| CVE-2023-36029(opens NVD record) | Medium | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Nov 3, 2023 |