Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1097/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-41301(opens NVD record) | High | 7.5 | Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Sep 25, 2023 |
| CVE-2023-41300(opens NVD record) | High | 7.5 | Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | Sep 25, 2023 |
| CVE-2023-41293(opens NVD record) | High | 7.5 | Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 25, 2023 |
| CVE-2022-48605(opens NVD record) | Critical | 9.8 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | Sep 25, 2023 |
| CVE-2023-41299(opens NVD record) | High | 7.5 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | Sep 25, 2023 |
| CVE-2023-41298(opens NVD record) | High | 7.5 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 25, 2023 |
| CVE-2023-41297(opens NVD record) | Critical | 9.8 | Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking. | Sep 25, 2023 |
| CVE-2023-41296(opens NVD record) | Critical | 9.1 | Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality. | Sep 25, 2023 |
| CVE-2023-41295(opens NVD record) | Medium | 5.3 | Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim. | Sep 25, 2023 |
| CVE-2023-41294(opens NVD record) | Critical | 9.8 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | Sep 25, 2023 |
| CVE-2023-39409(opens NVD record) | High | 7.5 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | Sep 25, 2023 |
| CVE-2023-39408(opens NVD record) | High | 7.5 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | Sep 25, 2023 |
| CVE-2023-39407(opens NVD record) | Critical | 9.1 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | Sep 25, 2023 |
| CVE-2023-1636(opens NVD record) | Medium | 6.0 | A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. | Sep 24, 2023 |
| CVE-2023-1633(opens NVD record) | Medium | 6.6 | A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. | Sep 24, 2023 |
| CVE-2023-1625(opens NVD record) | High | 7.4 | An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system. | Sep 24, 2023 |
| CVE-2023-1260(opens NVD record) | High | 8.0 | An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod. | Sep 24, 2023 |
| CVE-2022-3962(opens NVD record) | Medium | 4.3 | A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed. | Sep 23, 2023 |
| CVE-2022-4039(opens NVD record) | High | 8.0 | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration. | Sep 22, 2023 |
| CVE-2022-3874(opens NVD record) | High | 8.0 | A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system. | Sep 22, 2023 |
| CVE-2023-43767(opens NVD record) | High | 7.5 | Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 22, 2023 |
| CVE-2023-43766(opens NVD record) | High | 7.8 | Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 22, 2023 |
| CVE-2023-43765(opens NVD record) | High | 7.5 | Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 22, 2023 |
| CVE-2023-43761(opens NVD record) | High | 7.5 | Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 22, 2023 |
| CVE-2023-43760(opens NVD record) | High | 7.5 | Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 22, 2023 |
| CVE-2023-38344(opens NVD record) | Medium | 6.5 | An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access. | Sep 21, 2023 |
| CVE-2023-38343(opens NVD record) | High | 7.5 | An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery. | Sep 21, 2023 |
| CVE-2023-41993(opens NVD record) | High | 8.8 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | Sep 21, 2023 |
| CVE-2023-39252(opens NVD record) | Medium | 5.9 | Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. | Sep 21, 2023 |
| CVE-2023-22024(opens NVD record) | Medium | 5.5 | In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). | Sep 20, 2023 |
| CVE-2023-38718(opens NVD record) | Low | 3.7 | IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606. | Sep 20, 2023 |
| CVE-2023-37410(opens NVD record) | High | 8.4 | IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138. | Sep 20, 2023 |
| CVE-2022-3596(opens NVD record) | High | 7.5 | An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials. | Sep 20, 2023 |
| CVE-2023-40368(opens NVD record) | Medium | 4.4 | IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456. | Sep 20, 2023 |
| CVE-2023-42660(opens NVD record) | High | 8.8 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content. | Sep 20, 2023 |
| CVE-2023-42656(opens NVD record) | Medium | 6.1 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users during the package composition procedure. If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser. | Sep 20, 2023 |
| CVE-2023-40043(opens NVD record) | High | 7.2 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system administrator could submit a crafted payload to the MOVEit Transfer web interface which could result in modification and disclosure of MOVEit database content. | Sep 20, 2023 |
| CVE-2022-3916(opens NVD record) | Medium | 6.8 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user. | Sep 20, 2023 |
| CVE-2023-0462(opens NVD record) | High | 8.0 | An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload. | Sep 20, 2023 |
| CVE-2023-0118(opens NVD record) | Critical | 9.1 | An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system. | Sep 20, 2023 |
| CVE-2022-1438(opens NVD record) | Medium | 6.4 | A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability. | Sep 20, 2023 |
| CVE-2023-4236(opens NVD record) | High | 7.5 | A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1. | Sep 20, 2023 |
| CVE-2023-5042(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575. | Sep 20, 2023 |
| CVE-2023-4853(opens NVD record) | High | 8.1 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. | Sep 20, 2023 |
| CVE-2023-34047(opens NVD record) | Low | 3.1 | A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry. | Sep 20, 2023 |
| CVE-2023-31015(opens NVD record) | Medium | 6.6 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service. | Sep 20, 2023 |
| CVE-2023-31014(opens NVD record) | Medium | 4.2 | NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution. | Sep 20, 2023 |
| CVE-2023-31013(opens NVD record) | Medium | 6.1 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure. | Sep 20, 2023 |
| CVE-2023-31012(opens NVD record) | Medium | 6.1 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure. | Sep 20, 2023 |
| CVE-2023-31011(opens NVD record) | Medium | 5.2 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure. | Sep 20, 2023 |