Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1098/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-31010(opens NVD record) | Medium | 6.8 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, and denial of service. | Sep 20, 2023 |
| CVE-2023-38888(opens NVD record) | Critical | 9.6 | Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | Sep 20, 2023 |
| CVE-2023-38887(opens NVD record) | High | 8.8 | File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions. | Sep 20, 2023 |
| CVE-2023-38886(opens NVD record) | High | 7.2 | An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | Sep 20, 2023 |
| CVE-2023-31009(opens NVD record) | High | 8.3 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure. | Sep 20, 2023 |
| CVE-2023-31008(opens NVD record) | High | 7.3 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of services, escalation of privileges, and information disclosure. | Sep 20, 2023 |
| CVE-2023-25534(opens NVD record) | Medium | 5.7 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | Sep 20, 2023 |
| CVE-2023-25533(opens NVD record) | High | 8.3 | NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to information disclosure, code execution, and escalation of privileges. | Sep 20, 2023 |
| CVE-2023-25532(opens NVD record) | Medium | 6.5 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to information disclosure. | Sep 20, 2023 |
| CVE-2023-25531(opens NVD record) | High | 7.6 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and escalation of privileges. | Sep 20, 2023 |
| CVE-2023-25530(opens NVD record) | High | 8.0 | NVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure. | Sep 20, 2023 |
| CVE-2023-25529(opens NVD record) | High | 8.0 | NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering. | Sep 20, 2023 |
| CVE-2023-25528(opens NVD record) | High | 8.8 | NVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering. | Sep 20, 2023 |
| CVE-2023-25527(opens NVD record) | High | 7.8 | NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel memory. A successful exploit of this vulnerability may lead to arbitrary kernel code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | Sep 20, 2023 |
| CVE-2023-25526(opens NVD record) | Medium | 6.5 | NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may cause an uncaught exception by injecting a crafted packet. A successful exploit may lead to denial of service. | Sep 20, 2023 |
| CVE-2023-25525(opens NVD record) | High | 7.5 | NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure. | Sep 20, 2023 |
| CVE-2020-24089(opens NVD record) | Medium | 5.5 | An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DoS). | Sep 20, 2023 |
| CVE-2023-40934(opens NVD record) | High | 7.2 | A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. | Sep 19, 2023 |
| CVE-2023-40933(opens NVD record) | High | 8.8 | A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function. | Sep 19, 2023 |
| CVE-2023-40932(opens NVD record) | Medium | 5.4 | A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials. | Sep 19, 2023 |
| CVE-2023-40931(opens NVD record) | Medium | 6.5 | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | Sep 19, 2023 |
| CVE-2023-41179(opens NVD record) | High | 7.2 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | Sep 19, 2023 |
| CVE-2023-42399(opens NVD record) | Medium | 6.1 | Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component. | Sep 19, 2023 |
| CVE-2023-39056(opens NVD record) | Medium | 6.5 | An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39049(opens NVD record) | Medium | 6.5 | An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39046(opens NVD record) | Medium | 6.5 | An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39058(opens NVD record) | Medium | 6.5 | An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39043(opens NVD record) | Medium | 6.5 | An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39040(opens NVD record) | Medium | 6.5 | An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-39039(opens NVD record) | Medium | 6.5 | An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | Sep 18, 2023 |
| CVE-2023-4806(opens NVD record) | Medium | 5.9 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags. | Sep 18, 2023 |
| CVE-2023-4527(opens NVD record) | Medium | 6.5 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash. | Sep 18, 2023 |
| CVE-2023-41595(opens NVD record) | High | 7.5 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | Sep 18, 2023 |
| CVE-2023-43114(opens NVD record) | Medium | 5.5 | An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks. | Sep 18, 2023 |
| CVE-2023-42525(opens NVD record) | High | 7.5 | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42524(opens NVD record) | High | 7.5 | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42523(opens NVD record) | High | 7.5 | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42522(opens NVD record) | High | 7.5 | Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42521(opens NVD record) | High | 7.5 | Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42526(opens NVD record) | High | 7.5 | Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-42520(opens NVD record) | High | 7.5 | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. | Sep 18, 2023 |
| CVE-2023-36735(opens NVD record) | Critical | 9.6 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Sep 15, 2023 |
| CVE-2023-36727(opens NVD record) | Medium | 6.1 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Sep 15, 2023 |
| CVE-2023-36562(opens NVD record) | High | 7.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Sep 15, 2023 |
| CVE-2023-0923(opens NVD record) | High | 8.8 | A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues. | Sep 15, 2023 |
| CVE-2023-0813(opens NVD record) | High | 7.5 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication. | Sep 15, 2023 |
| CVE-2022-3261(opens NVD record) | Medium | 4.4 | A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. | Sep 15, 2023 |
| CVE-2022-3466(opens NVD record) | Medium | 4.8 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652. | Sep 15, 2023 |
| CVE-2023-4959(opens NVD record) | Medium | 6.5 | A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled request from another domain, it is possible to reconfigure the Quay instance (including adding users with admin privileges). | Sep 15, 2023 |
| CVE-2023-32461(opens NVD record) | Medium | 5.0 | Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges. | Sep 15, 2023 |