Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1096/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-44205(opens NVD record) | Medium | 5.3 | Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44161(opens NVD record) | Medium | 6.5 | Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44160(opens NVD record) | Medium | 6.5 | Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44159(opens NVD record) | High | 7.5 | Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44158(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44157(opens NVD record) | High | 7.8 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44156(opens NVD record) | High | 7.5 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44155(opens NVD record) | High | 7.5 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44154(opens NVD record) | High | 8.1 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44153(opens NVD record) | High | 7.5 | Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44152(opens NVD record) | Critical | 9.1 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-43856(opens NVD record) | High | 7.5 | Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java. | Sep 27, 2023 |
| CVE-2023-43234(opens NVD record) | Critical | 9.8 | DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters. | Sep 27, 2023 |
| CVE-2023-43232(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter. | Sep 27, 2023 |
| CVE-2023-42657(opens NVD record) | Critical | 9.9 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system. | Sep 27, 2023 |
| CVE-2023-41904(opens NVD record) | Medium | 5.4 | Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. | Sep 27, 2023 |
| CVE-2023-41312(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically. | Sep 27, 2023 |
| CVE-2023-41311(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically. | Sep 27, 2023 |
| CVE-2023-41310(opens NVD record) | Low | 3.3 | Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background. | Sep 27, 2023 |
| CVE-2023-41309(opens NVD record) | High | 7.5 | Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-41308(opens NVD record) | High | 7.5 | Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 27, 2023 |
| CVE-2023-41307(opens NVD record) | High | 7.5 | Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-41306(opens NVD record) | Low | 3.7 | Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable. | Sep 27, 2023 |
| CVE-2023-41305(opens NVD record) | High | 7.5 | Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 27, 2023 |
| CVE-2023-40049(opens NVD record) | Medium | 5.3 | In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing. | Sep 27, 2023 |
| CVE-2023-40048(opens NVD record) | Medium | 6.8 | In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function. | Sep 27, 2023 |
| CVE-2023-40047(opens NVD record) | High | 8.3 | In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads. Once the cross-site scripting payload is successfully stored, an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser. | Sep 27, 2023 |
| CVE-2023-40046(opens NVD record) | High | 8.2 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements. | Sep 27, 2023 |
| CVE-2023-40045(opens NVD record) | High | 8.3 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module. An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser. | Sep 27, 2023 |
| CVE-2023-40044(opens NVD record) | Critical | 10.0 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | Sep 27, 2023 |
| CVE-2023-3223(opens NVD record) | High | 7.5 | A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null. | Sep 27, 2023 |
| CVE-2023-36851(opens NVD record) | Medium | 5.3 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2. | Sep 27, 2023 |
| CVE-2023-34043(opens NVD record) | Medium | 6.7 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | Sep 27, 2023 |
| CVE-2023-28055(opens NVD record) | High | 8.8 | Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity. | Sep 27, 2023 |
| CVE-2023-0833(opens NVD record) | Medium | 4.7 | A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions. | Sep 27, 2023 |
| CVE-2023-0456(opens NVD record) | High | 7.4 | A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorized information. | Sep 27, 2023 |
| CVE-2022-48606(opens NVD record) | High | 7.5 | Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-43278(opens NVD record) | High | 8.8 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account. | Sep 25, 2023 |
| CVE-2023-42753(opens NVD record) | High | 7.0 | An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. | Sep 25, 2023 |
| CVE-2023-42426(opens NVD record) | Medium | 6.1 | Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component. | Sep 25, 2023 |
| CVE-2022-4318(opens NVD record) | High | 7.8 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | Sep 25, 2023 |
| CVE-2022-4245(opens NVD record) | Medium | 4.3 | A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection. | Sep 25, 2023 |
| CVE-2022-4244(opens NVD record) | High | 7.5 | A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files. | Sep 25, 2023 |
| CVE-2022-4137(opens NVD record) | High | 8.1 | A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker. | Sep 25, 2023 |
| CVE-2023-40581(opens NVD record) | High | 8.3 | yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stages in its download steps through the `--exec` flag. This flag allows output template expansion in its argument, so that metadata values may be used in the shell commands. The metadata fields can be combined with the `%q` conversion, which is intended to quote/escape these values so they can be safely passed to the shell. However, the escaping used for `cmd` (the shell used by Python's `subprocess` on Windows) does not properly escape special characters, which can allow for remote code execution if `--exec` is used directly with maliciously crafted remote data. This vulnerability only impacts `yt-dlp` on Windows, and the vulnerability is present regardless of whether `yt-dlp` is run from `cmd` or from `PowerShell`. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2023.09.24 fixes this issue by properly escaping each special character. `\n` will be replaced by `\r` as no way of escaping it has been found. It is recommended to upgrade yt-dlp to version 2023.09.24 as soon as possible. Also, always be careful when using --exec, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade: 1. Avoid using any output template expansion in --exec other than {} (filepath). 2. If expansion in --exec is needed, verify the fields you are using do not contain ", | or &. 3. Instead of using --exec, write the info json and load the fields from it instead. | Sep 25, 2023 |
| CVE-2023-4156(opens NVD record) | Medium | 4.4 | A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information. | Sep 25, 2023 |
| CVE-2023-5156(opens NVD record) | High | 7.5 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash. | Sep 25, 2023 |
| CVE-2023-43141(opens NVD record) | Critical | 9.8 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. | Sep 25, 2023 |
| CVE-2023-41303(opens NVD record) | High | 7.5 | Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified. | Sep 25, 2023 |
| CVE-2023-41302(opens NVD record) | High | 7.5 | Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Sep 25, 2023 |