Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1108/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-39390(opens NVD record) | High | 7.5 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | Aug 13, 2023 |
| CVE-2023-39387(opens NVD record) | Medium | 5.3 | Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. | Aug 13, 2023 |
| CVE-2023-39386(opens NVD record) | High | 7.5 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | Aug 13, 2023 |
| CVE-2023-39385(opens NVD record) | Critical | 9.1 | Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access. | Aug 13, 2023 |
| CVE-2021-46895(opens NVD record) | Critical | 9.1 | Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop. | Aug 13, 2023 |
| CVE-2023-39405(opens NVD record) | Critical | 9.8 | Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges. | Aug 13, 2023 |
| CVE-2023-39396(opens NVD record) | High | 7.5 | Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability. | Aug 13, 2023 |
| CVE-2023-39393(opens NVD record) | High | 7.5 | Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten. | Aug 13, 2023 |
| CVE-2023-39392(opens NVD record) | High | 7.5 | Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten. | Aug 13, 2023 |
| CVE-2023-39389(opens NVD record) | High | 7.5 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | Aug 13, 2023 |
| CVE-2023-39388(opens NVD record) | High | 7.5 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | Aug 13, 2023 |
| CVE-2023-39384(opens NVD record) | High | 7.5 | Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally. | Aug 13, 2023 |
| CVE-2023-39383(opens NVD record) | High | 7.5 | Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security. | Aug 13, 2023 |
| CVE-2023-39382(opens NVD record) | High | 7.5 | Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart. | Aug 13, 2023 |
| CVE-2023-39381(opens NVD record) | High | 7.5 | Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart. | Aug 13, 2023 |
| CVE-2023-39380(opens NVD record) | High | 7.5 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. | Aug 13, 2023 |
| CVE-2023-32267(opens NVD record) | Medium | 6.4 | A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited. | Aug 11, 2023 |
| CVE-2020-35990(opens NVD record) | Medium | 5.5 | Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file. | Aug 11, 2023 |
| CVE-2020-27449(opens NVD record) | Medium | 6.1 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload. | Aug 11, 2023 |
| CVE-2023-39418(opens NVD record) | Low | 3.1 | A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows. | Aug 11, 2023 |
| CVE-2023-39417(opens NVD record) | High | 7.5 | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | Aug 11, 2023 |
| CVE-2023-3937(opens NVD record) | Medium | 4.8 | Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | Aug 11, 2023 |
| CVE-2023-3864(opens NVD record) | High | 7.2 | Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | Aug 11, 2023 |
| CVE-2023-28714(opens NVD record) | High | 8.2 | Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. | Aug 11, 2023 |
| CVE-2023-28385(opens NVD record) | High | 8.2 | Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access. | Aug 11, 2023 |
| CVE-2022-40982(opens NVD record) | Medium | 6.5 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Aug 11, 2023 |
| CVE-2023-35179(opens NVD record) | High | 7.2 | A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. | Aug 11, 2023 |
| CVE-2023-40225(opens NVD record) | High | 7.2 | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request. | Aug 10, 2023 |
| CVE-2023-38333(opens NVD record) | Medium | 6.1 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | Aug 10, 2023 |
| CVE-2023-39806(opens NVD record) | Critical | 9.8 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | Aug 10, 2023 |
| CVE-2023-39805(opens NVD record) | Critical | 9.8 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. | Aug 10, 2023 |
| CVE-2023-32565(opens NVD record) | Critical | 9.1 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1. | Aug 10, 2023 |
| CVE-2023-32564(opens NVD record) | Critical | 9.8 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | Aug 10, 2023 |
| CVE-2023-32563(opens NVD record) | Critical | 9.8 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. | Aug 10, 2023 |
| CVE-2023-32562(opens NVD record) | Critical | 9.8 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1. | Aug 10, 2023 |
| CVE-2023-32561(opens NVD record) | High | 7.5 | A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1. | Aug 10, 2023 |
| CVE-2023-32560(opens NVD record) | Critical | 9.8 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1. | Aug 10, 2023 |
| CVE-2023-28129(opens NVD record) | High | 7.8 | DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user. | Aug 10, 2023 |
| CVE-2023-38034(opens NVD record) | Critical | 9.8 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update UniFi Switches to Version 6.5.59 or later. | Aug 10, 2023 |
| CVE-2023-35085(opens NVD record) | Critical | 9.8 | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later. | Aug 10, 2023 |
| CVE-2023-32567(opens NVD record) | Critical | 9.8 | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 | Aug 10, 2023 |
| CVE-2023-32566(opens NVD record) | Critical | 9.1 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1. | Aug 10, 2023 |
| CVE-2023-38248(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38247(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38246(opens NVD record) | High | 7.8 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38245(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must open a maliciously crafted Microsoft Office file, or visit an attacker controlled web page. | Aug 10, 2023 |
| CVE-2023-38244(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38243(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38242(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |
| CVE-2023-38241(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Aug 10, 2023 |