Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,758 matching · page 1110/1336Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-5168(opens NVD record) | Critical | 9.8 | A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. | Sep 27, 2023 |
| CVE-2023-5157(opens NVD record) | High | 7.5 | A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. | Sep 27, 2023 |
| CVE-2023-4565(opens NVD record) | Medium | 5.3 | Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable. | Sep 27, 2023 |
| CVE-2023-4065(opens NVD record) | Medium | 5.5 | A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions. | Sep 27, 2023 |
| CVE-2023-4003(opens NVD record) | High | 7.6 | One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges. | Sep 27, 2023 |
| CVE-2023-44216(opens NVD record) | Medium | 5.3 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin. | Sep 27, 2023 |
| CVE-2023-44207(opens NVD record) | Medium | 5.4 | Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44206(opens NVD record) | Critical | 9.1 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44205(opens NVD record) | Medium | 5.3 | Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44161(opens NVD record) | Medium | 6.5 | Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44160(opens NVD record) | Medium | 6.5 | Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44159(opens NVD record) | High | 7.5 | Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44158(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44157(opens NVD record) | High | 7.8 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44156(opens NVD record) | High | 7.5 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44155(opens NVD record) | High | 7.5 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44154(opens NVD record) | High | 8.1 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44153(opens NVD record) | High | 7.5 | Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-44152(opens NVD record) | Critical | 9.1 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | Sep 27, 2023 |
| CVE-2023-43856(opens NVD record) | High | 7.5 | Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java. | Sep 27, 2023 |
| CVE-2023-43234(opens NVD record) | Critical | 9.8 | DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters. | Sep 27, 2023 |
| CVE-2023-43232(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter. | Sep 27, 2023 |
| CVE-2023-42657(opens NVD record) | Critical | 9.9 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system. | Sep 27, 2023 |
| CVE-2023-41904(opens NVD record) | Medium | 5.4 | Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. | Sep 27, 2023 |
| CVE-2023-41312(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically. | Sep 27, 2023 |
| CVE-2023-41311(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically. | Sep 27, 2023 |
| CVE-2023-41310(opens NVD record) | Low | 3.3 | Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background. | Sep 27, 2023 |
| CVE-2023-41309(opens NVD record) | High | 7.5 | Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-41308(opens NVD record) | High | 7.5 | Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 27, 2023 |
| CVE-2023-41307(opens NVD record) | High | 7.5 | Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-41306(opens NVD record) | Low | 3.7 | Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable. | Sep 27, 2023 |
| CVE-2023-41305(opens NVD record) | High | 7.5 | Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. | Sep 27, 2023 |
| CVE-2023-40049(opens NVD record) | Medium | 5.3 | In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing. | Sep 27, 2023 |
| CVE-2023-40048(opens NVD record) | Medium | 6.8 | In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function. | Sep 27, 2023 |
| CVE-2023-40047(opens NVD record) | High | 8.3 | In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads. Once the cross-site scripting payload is successfully stored, an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser. | Sep 27, 2023 |
| CVE-2023-40046(opens NVD record) | High | 8.2 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements. | Sep 27, 2023 |
| CVE-2023-40045(opens NVD record) | High | 8.3 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module. An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser. | Sep 27, 2023 |
| CVE-2023-40044(opens NVD record) | Critical | 10.0 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | Sep 27, 2023 |
| CVE-2023-3223(opens NVD record) | High | 7.5 | A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null. | Sep 27, 2023 |
| CVE-2023-36851(opens NVD record) | Medium | 5.3 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2. | Sep 27, 2023 |
| CVE-2023-34043(opens NVD record) | Medium | 6.7 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | Sep 27, 2023 |
| CVE-2023-28055(opens NVD record) | High | 8.8 | Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity. | Sep 27, 2023 |
| CVE-2023-0833(opens NVD record) | Medium | 4.7 | A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions. | Sep 27, 2023 |
| CVE-2023-0456(opens NVD record) | High | 7.4 | A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorized information. | Sep 27, 2023 |
| CVE-2022-48606(opens NVD record) | High | 7.5 | Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability. | Sep 27, 2023 |
| CVE-2023-43278(opens NVD record) | High | 8.8 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account. | Sep 25, 2023 |
| CVE-2023-42753(opens NVD record) | High | 7.0 | An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. | Sep 25, 2023 |
| CVE-2023-42426(opens NVD record) | Medium | 6.1 | Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component. | Sep 25, 2023 |
| CVE-2022-4318(opens NVD record) | High | 7.8 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | Sep 25, 2023 |
| CVE-2022-4245(opens NVD record) | Medium | 4.3 | A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection. | Sep 25, 2023 |