Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1107/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-32487(opens NVD record) | High | 7.8 | Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure. | Aug 16, 2023 |
| CVE-2023-32486(opens NVD record) | Medium | 6.7 | Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges. | Aug 16, 2023 |
| CVE-2023-32494(opens NVD record) | Medium | 6.7 | Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also. | Aug 16, 2023 |
| CVE-2020-26037(opens NVD record) | Critical | 9.8 | Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code. | Aug 16, 2023 |
| CVE-2023-20564(opens NVD record) | Medium | 6.7 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution. | Aug 15, 2023 |
| CVE-2023-20560(opens NVD record) | Medium | 4.4 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. | Aug 15, 2023 |
| CVE-2023-4344(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection | Aug 15, 2023 |
| CVE-2023-4343(opens NVD record) | High | 7.5 | Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter | Aug 15, 2023 |
| CVE-2023-4342(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy | Aug 15, 2023 |
| CVE-2023-4341(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI | Aug 15, 2023 |
| CVE-2023-4340(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file | Aug 15, 2023 |
| CVE-2023-4339(opens NVD record) | High | 7.5 | Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions | Aug 15, 2023 |
| CVE-2023-4338(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers | Aug 15, 2023 |
| CVE-2023-4337(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation | Aug 15, 2023 |
| CVE-2023-4336(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute | Aug 15, 2023 |
| CVE-2023-4335(opens NVD record) | High | 7.5 | Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux | Aug 15, 2023 |
| CVE-2023-4334(opens NVD record) | High | 7.5 | Broadcom RAID Controller Web server (nginx) is serving private files without any authentication | Aug 15, 2023 |
| CVE-2023-4333(opens NVD record) | Medium | 5.5 | Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server | Aug 15, 2023 |
| CVE-2023-4332(opens NVD record) | High | 7.5 | Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file | Aug 15, 2023 |
| CVE-2023-4331(opens NVD record) | High | 7.5 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols | Aug 15, 2023 |
| CVE-2023-4329(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute | Aug 15, 2023 |
| CVE-2023-4328(opens NVD record) | Medium | 5.5 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows | Aug 15, 2023 |
| CVE-2023-4327(opens NVD record) | Medium | 5.5 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux | Aug 15, 2023 |
| CVE-2023-4326(opens NVD record) | High | 7.5 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites | Aug 15, 2023 |
| CVE-2023-4325(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | Aug 15, 2023 |
| CVE-2023-4324(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | Aug 15, 2023 |
| CVE-2023-4323(opens NVD record) | Critical | 9.8 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | Aug 15, 2023 |
| CVE-2023-38402(opens NVD record) | High | 7.1 | A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process. | Aug 15, 2023 |
| CVE-2023-38401(opens NVD record) | High | 7.8 | A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system. | Aug 15, 2023 |
| CVE-2023-4345(opens NVD record) | Medium | 6.5 | Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user | Aug 15, 2023 |
| CVE-2023-35082(opens NVD record) | Critical | 9.8 | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier. | Aug 15, 2023 |
| CVE-2023-38741(opens NVD record) | High | 7.5 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 262905. | Aug 14, 2023 |
| CVE-2023-38721(opens NVD record) | High | 8.4 | The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173. | Aug 14, 2023 |
| CVE-2023-30188(opens NVD record) | High | 7.5 | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file. | Aug 14, 2023 |
| CVE-2023-30187(opens NVD record) | Critical | 9.8 | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | Aug 14, 2023 |
| CVE-2023-30186(opens NVD record) | Critical | 9.8 | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | Aug 14, 2023 |
| CVE-2023-37847(opens NVD record) | Critical | 9.8 | novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. | Aug 14, 2023 |
| CVE-2023-23208(opens NVD record) | Medium | 6.1 | Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. | Aug 13, 2023 |
| CVE-2023-39406(opens NVD record) | High | 7.5 | Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart. | Aug 13, 2023 |
| CVE-2023-39404(opens NVD record) | High | 7.5 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | Aug 13, 2023 |
| CVE-2023-39403(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39402(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39401(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39400(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39399(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39398(opens NVD record) | Critical | 9.1 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | Aug 13, 2023 |
| CVE-2023-39397(opens NVD record) | High | 7.5 | Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability. | Aug 13, 2023 |
| CVE-2023-39395(opens NVD record) | High | 7.5 | Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability. | Aug 13, 2023 |
| CVE-2023-39394(opens NVD record) | High | 7.5 | Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified. | Aug 13, 2023 |
| CVE-2023-39391(opens NVD record) | High | 7.5 | Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality. | Aug 13, 2023 |