Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,854 matching · page 1134/1338Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-34125(opens NVD record) | Medium | 6.5 | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | Jul 13, 2023 |
| CVE-2023-34124(opens NVD record) | Critical | 9.8 | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | Jul 13, 2023 |
| CVE-2023-34123(opens NVD record) | High | 7.5 | Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | Jul 13, 2023 |
| CVE-2023-38046(opens NVD record) | Medium | 5.5 | A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. | Jul 12, 2023 |
| CVE-2023-29319(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29318(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29317(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29316(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29315(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29314(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29313(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29312(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29311(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29310(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29309(opens NVD record) | Medium | 5.5 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-29308(opens NVD record) | High | 7.8 | Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 12, 2023 |
| CVE-2023-3618(opens NVD record) | Medium | 6.5 | A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service. | Jul 12, 2023 |
| CVE-2023-20210(opens NVD record) | Medium | 6.0 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device. | Jul 12, 2023 |
| CVE-2023-20207(opens NVD record) | Medium | 4.9 | A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to view sensitive information in clear text. | Jul 12, 2023 |
| CVE-2023-20185(opens NVD record) | High | 7.4 | A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites. Cisco has not released and will not release software updates that address this vulnerability. | Jul 12, 2023 |
| CVE-2023-33668(opens NVD record) | Critical | 9.8 | DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers. | Jul 12, 2023 |
| CVE-2020-20021(opens NVD record) | High | 7.5 | An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. | Jul 12, 2023 |
| CVE-2021-44696(opens NVD record) | Low | 3.3 | Adobe Prelude version 22.1.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious JPEG file. | Jul 12, 2023 |
| CVE-2021-43760(opens NVD record) | Low | 3.3 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious MOV file. | Jul 12, 2023 |
| CVE-2021-43759(opens NVD record) | Low | 3.3 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious MP4 file. | Jul 12, 2023 |
| CVE-2021-43758(opens NVD record) | Low | 3.3 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious MP4 file. | Jul 12, 2023 |
| CVE-2021-43757(opens NVD record) | High | 7.8 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious 3GP file | Jul 12, 2023 |
| CVE-2023-24492(opens NVD record) | Critical | 9.6 | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts. | Jul 11, 2023 |
| CVE-2023-24491(opens NVD record) | High | 7.8 | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM. | Jul 11, 2023 |
| CVE-2023-36884(opens NVD record) | High | 7.5 | Windows Search Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-36874(opens NVD record) | High | 7.8 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-36872(opens NVD record) | Medium | 5.5 | VP9 Video Extensions Information Disclosure Vulnerability | Jul 11, 2023 |
| CVE-2023-36871(opens NVD record) | Medium | 6.5 | Azure Active Directory Security Feature Bypass Vulnerability | Jul 11, 2023 |
| CVE-2023-36868(opens NVD record) | Medium | 6.5 | Azure Service Fabric on Windows Information Disclosure Vulnerability | Jul 11, 2023 |
| CVE-2023-35374(opens NVD record) | High | 7.8 | Paint 3D Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-35373(opens NVD record) | Medium | 5.3 | Mono Authenticode Validation Spoofing Vulnerability | Jul 11, 2023 |
| CVE-2023-35367(opens NVD record) | Critical | 9.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-35366(opens NVD record) | Critical | 9.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-35365(opens NVD record) | Critical | 9.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-35364(opens NVD record) | High | 8.8 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35363(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35362(opens NVD record) | High | 7.8 | Windows Clip Service Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35361(opens NVD record) | High | 7.0 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35360(opens NVD record) | High | 7.0 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35358(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35357(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35356(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35353(opens NVD record) | High | 7.8 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-35352(opens NVD record) | High | 7.5 | Windows Remote Desktop Security Feature Bypass Vulnerability | Jul 11, 2023 |
| CVE-2023-35351(opens NVD record) | Medium | 6.6 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | Jul 11, 2023 |