Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,849 matching · page 1137/1337Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-32038(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-32037(opens NVD record) | Medium | 6.5 | Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | Jul 11, 2023 |
| CVE-2023-32035(opens NVD record) | Medium | 6.5 | Remote Procedure Call Runtime Denial of Service Vulnerability | Jul 11, 2023 |
| CVE-2023-32034(opens NVD record) | Medium | 6.5 | Remote Procedure Call Runtime Denial of Service Vulnerability | Jul 11, 2023 |
| CVE-2023-32033(opens NVD record) | Medium | 6.6 | Microsoft Failover Cluster Remote Code Execution Vulnerability | Jul 11, 2023 |
| CVE-2023-29347(opens NVD record) | High | 8.7 | Windows Admin Center Spoofing Vulnerability | Jul 11, 2023 |
| CVE-2023-21756(opens NVD record) | High | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | Jul 11, 2023 |
| CVE-2023-21526(opens NVD record) | High | 7.4 | Windows Netlogon Information Disclosure Vulnerability | Jul 11, 2023 |
| CVE-2023-3354(opens NVD record) | High | 7.5 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. | Jul 11, 2023 |
| CVE-2023-28001(opens NVD record) | Medium | 4.1 | An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API. | Jul 11, 2023 |
| CVE-2023-25606(opens NVD record) | Medium | 6.5 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | Jul 11, 2023 |
| CVE-2023-24881(opens NVD record) | Medium | 6.5 | Microsoft Teams Information Disclosure Vulnerability | Jul 11, 2023 |
| CVE-2022-23447(opens NVD record) | High | 7.5 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | Jul 11, 2023 |
| CVE-2023-3617(opens NVD record) | High | 7.3 | A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233565 was assigned to this vulnerability. | Jul 11, 2023 |
| CVE-2023-31818(opens NVD record) | High | 7.5 | An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function. | Jul 11, 2023 |
| CVE-2020-20118(opens NVD record) | Medium | 5.5 | Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver. | Jul 11, 2023 |
| CVE-2023-3269(opens NVD record) | High | 7.8 | A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges. | Jul 11, 2023 |
| CVE-2023-1672(opens NVD record) | Medium | 5.3 | A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host. | Jul 11, 2023 |
| CVE-2023-23777(opens NVD record) | High | 7.2 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters. | Jul 11, 2023 |
| CVE-2022-22302(opens NVD record) | Medium | 5.3 | A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem. | Jul 11, 2023 |
| CVE-2023-24490(opens NVD record) | Medium | 6.3 | Users with only access to launch VDA applications can launch an unauthorized desktop | Jul 10, 2023 |
| CVE-2023-24489(opens NVD record) | Critical | 9.8 | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | Jul 10, 2023 |
| CVE-2023-34432(opens NVD record) | High | 7.8 | A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. | Jul 10, 2023 |
| CVE-2023-24488(opens NVD record) | Medium | 6.1 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | Jul 10, 2023 |
| CVE-2023-24487(opens NVD record) | Medium | 6.3 | Arbitrary file read in Citrix ADC and Citrix Gateway | Jul 10, 2023 |
| CVE-2023-24486(opens NVD record) | Medium | 5.5 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | Jul 10, 2023 |
| CVE-2023-34318(opens NVD record) | High | 7.8 | A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. | Jul 10, 2023 |
| CVE-2023-32627(opens NVD record) | Medium | 6.2 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. | Jul 10, 2023 |
| CVE-2023-26590(opens NVD record) | Medium | 6.2 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. | Jul 10, 2023 |
| CVE-2023-32254(opens NVD record) | Critical | 9.8 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. | Jul 10, 2023 |
| CVE-2023-32250(opens NVD record) | Critical | 9.0 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. | Jul 10, 2023 |
| CVE-2023-30449(opens NVD record) | High | 7.5 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439. | Jul 10, 2023 |
| CVE-2023-30448(opens NVD record) | Medium | 5.9 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437. | Jul 10, 2023 |
| CVE-2023-30447(opens NVD record) | Medium | 5.9 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436. | Jul 10, 2023 |
| CVE-2023-30446(opens NVD record) | Medium | 5.9 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 . | Jul 10, 2023 |
| CVE-2023-30445(opens NVD record) | High | 7.5 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357. | Jul 10, 2023 |
| CVE-2023-30442(opens NVD record) | Medium | 5.9 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server may crash when using a specially crafted wrapper using certain options. IBM X-Force ID: 253202. | Jul 10, 2023 |
| CVE-2023-30431(opens NVD record) | High | 8.4 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184. | Jul 10, 2023 |
| CVE-2023-29256(opens NVD record) | Medium | 5.3 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046. | Jul 10, 2023 |
| CVE-2023-28958(opens NVD record) | High | 7.0 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. | Jul 10, 2023 |
| CVE-2023-28955(opens NVD record) | Medium | 6.5 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. | Jul 10, 2023 |
| CVE-2023-28953(opens NVD record) | Low | 3.1 | IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465. | Jul 10, 2023 |
| CVE-2023-27869(opens NVD record) | Medium | 6.3 | IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517. | Jul 10, 2023 |
| CVE-2023-27868(opens NVD record) | Medium | 6.3 | IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516. | Jul 10, 2023 |
| CVE-2023-27867(opens NVD record) | Medium | 6.3 | IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514. | Jul 10, 2023 |
| CVE-2023-27558(opens NVD record) | High | 8.4 | IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194. | Jul 10, 2023 |
| CVE-2023-27540(opens NVD record) | Medium | 5.9 | IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924. | Jul 10, 2023 |
| CVE-2023-23487(opens NVD record) | Medium | 4.3 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918. | Jul 10, 2023 |
| CVE-2023-1183(opens NVD record) | Medium | 5.0 | A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. | Jul 10, 2023 |
| CVE-2021-42083(opens NVD record) | High | 8.7 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * click add * click apply * create a test alert * The test alert will run the command “id | tee /tmp/ttttttddddssss” as root. * after the test alert inspect /tmp/ttttttddddssss it'll contain the ids of the root user. | Jul 10, 2023 |