Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,854 matching · page 1127/1338Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-35387(opens NVD record) | High | 8.8 | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35386(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35385(opens NVD record) | Critical | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-35384(opens NVD record) | Medium | 5.4 | Windows HTML Platforms Security Feature Bypass Vulnerability | Aug 8, 2023 |
| CVE-2023-35383(opens NVD record) | High | 7.5 | Microsoft Message Queuing Information Disclosure Vulnerability | Aug 8, 2023 |
| CVE-2023-35382(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35381(opens NVD record) | High | 8.8 | Windows Fax Service Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-35380(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35379(opens NVD record) | High | 7.8 | Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35378(opens NVD record) | High | 7.0 | Windows Projected File System Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-35377(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Aug 8, 2023 |
| CVE-2023-35376(opens NVD record) | Medium | 6.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Aug 8, 2023 |
| CVE-2023-35372(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-35371(opens NVD record) | High | 7.8 | Microsoft Office Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-35368(opens NVD record) | High | 8.8 | Microsoft Exchange Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-35359(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-29330(opens NVD record) | High | 8.8 | Microsoft Teams Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-29328(opens NVD record) | High | 8.8 | Microsoft Teams Remote Code Execution Vulnerability | Aug 8, 2023 |
| CVE-2023-21709(opens NVD record) | Critical | 9.8 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Aug 8, 2023 |
| CVE-2023-20588(opens NVD record) | Medium | 5.5 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | Aug 8, 2023 |
| CVE-2023-20569(opens NVD record) | Medium | 4.7 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | Aug 8, 2023 |
| CVE-2023-20562(opens NVD record) | High | 7.8 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution. | Aug 8, 2023 |
| CVE-2023-20561(opens NVD record) | Medium | 5.5 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service. | Aug 8, 2023 |
| CVE-2023-20556(opens NVD record) | Medium | 5.5 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service. | Aug 8, 2023 |
| CVE-2023-37646(opens NVD record) | High | 7.8 | An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal. | Aug 8, 2023 |
| CVE-2023-37690(opens NVD record) | Medium | 4.8 | Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page. | Aug 8, 2023 |
| CVE-2023-37689(opens NVD record) | Medium | 4.8 | Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page. | Aug 8, 2023 |
| CVE-2023-37688(opens NVD record) | Medium | 4.8 | Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page. | Aug 8, 2023 |
| CVE-2023-37687(opens NVD record) | High | 7.2 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal. | Aug 8, 2023 |
| CVE-2023-37686(opens NVD record) | Medium | 4.8 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal. | Aug 8, 2023 |
| CVE-2023-37685(opens NVD record) | Medium | 4.8 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal. | Aug 8, 2023 |
| CVE-2023-37684(opens NVD record) | Medium | 4.8 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal. | Aug 8, 2023 |
| CVE-2023-37683(opens NVD record) | Medium | 4.8 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin. | Aug 8, 2023 |
| CVE-2023-36054(opens NVD record) | Medium | 6.5 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count. | Aug 7, 2023 |
| CVE-2023-38157(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Aug 7, 2023 |
| CVE-2023-32783(opens NVD record) | High | 7.5 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | Aug 7, 2023 |
| CVE-2023-4194(opens NVD record) | Medium | 5.5 | A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket uid"), - 66b2c338adce ("tap: tap_open(): correctly initialize socket uid"), pass "inode->i_uid" to sock_init_data_uid() as the last parameter and that turns out to not be accurate. | Aug 7, 2023 |
| CVE-2023-4147(opens NVD record) | High | 7.8 | A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | Aug 7, 2023 |
| CVE-2023-36095(opens NVD record) | Critical | 9.8 | An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt. | Aug 5, 2023 |
| CVE-2022-46782(opens NVD record) | High | 7.8 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. | Aug 5, 2023 |
| CVE-2020-26082(opens NVD record) | Medium | 5.8 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerability by sending a malicious file inside a crafted zip-compressed file to an affected device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email. | Aug 4, 2023 |
| CVE-2020-26065(opens NVD record) | Medium | 6.5 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system. | Aug 4, 2023 |
| CVE-2020-26064(opens NVD record) | High | 8.1 | A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application. | Aug 4, 2023 |
| CVE-2023-38332(opens NVD record) | Medium | 6.5 | Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure. | Aug 4, 2023 |
| CVE-2023-0264(opens NVD record) | Medium | 5.0 | A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability. | Aug 4, 2023 |
| CVE-2023-39143(opens NVD record) | Critical | 9.8 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). | Aug 4, 2023 |
| CVE-2023-29505(opens NVD record) | Medium | 4.3 | An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking. | Aug 4, 2023 |
| CVE-2023-34038(opens NVD record) | Medium | 5.3 | VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration. | Aug 4, 2023 |
| CVE-2023-34037(opens NVD record) | Medium | 5.3 | VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. | Aug 4, 2023 |
| CVE-2023-36159(opens NVD record) | Medium | 6.1 | Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page. | Aug 4, 2023 |