Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1145/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-28956(opens NVD record) | High | 8.4 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | Jun 22, 2023 |
| CVE-2023-2911(opens NVD record) | High | 7.5 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1. | Jun 21, 2023 |
| CVE-2023-2829(opens NVD record) | High | 7.5 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1. | Jun 21, 2023 |
| CVE-2023-2828(opens NVD record) | High | 7.5 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1. | Jun 21, 2023 |
| CVE-2023-0026(opens NVD record) | High | 7.5 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, this session will be torn down with an update message error. This issue cannot propagate beyond an affected system as the processing error occurs as soon as the update is received. This issue is exploitable remotely as the respective attribute can propagate through unaffected systems and intermediate AS (if any). Continuous receipt of a BGP update containing this attribute will create a sustained Denial of Service (DoS) condition. Some customers have experienced these BGP session flaps which prompted Juniper SIRT to release this advisory out of cycle before fixed releases are widely available as there is an effective workaround. This issue affects: Juniper Networks Junos OS 15.1R1 and later versions prior to 20.4R3-S8; 21.1 version 21.1R1 and later versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S4; 22.2 versions prior to 22.2R3-S2; 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; 22.4 versions prior to 22.4R2-S1, 22.4R3; 23.1 versions prior to 23.1R1-S1, 23.1R2. Juniper Networks Junos OS Evolved All versions prior to 20.4R3-S8-EVO; 21.1 version 21.1R1-EVO and later versions prior to 21.2R3-S6-EVO; 21.3 versions prior to 21.3R3-S5-EVO; 21.4 versions prior to 21.4R3-S4-EVO; 22.1 versions prior to 22.1R3-S4-EVO; 22.2 versions prior to 22.2R3-S2-EVO; 22.3 versions prior to 22.3R2-S2-EVO, 22.3R3-S1-EVO; 22.4 versions prior to 22.4R2-S1-EVO, 22.4R3-EVO; 23.1 versions prior to 23.1R1-S1-EVO, 23.1R2-EVO. | Jun 21, 2023 |
| CVE-2023-27243(opens NVD record) | High | 7.5 | An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API. | Jun 21, 2023 |
| CVE-2022-45287(opens NVD record) | High | 8.8 | An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands. | Jun 21, 2023 |
| CVE-2023-35854(opens NVD record) | Critical | 9.8 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability." | Jun 20, 2023 |
| CVE-2023-34167(opens NVD record) | Medium | 5.3 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | Jun 19, 2023 |
| CVE-2023-34166(opens NVD record) | High | 7.5 | Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart. | Jun 19, 2023 |
| CVE-2023-34163(opens NVD record) | High | 7.5 | Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally. | Jun 19, 2023 |
| CVE-2023-34162(opens NVD record) | High | 7.5 | Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may cause repeated HMS Core updates and cause services to fail. | Jun 19, 2023 |
| CVE-2023-34161(opens NVD record) | High | 7.5 | nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability may cause features to perform abnormally. | Jun 19, 2023 |
| CVE-2023-34160(opens NVD record) | Medium | 5.3 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | Jun 19, 2023 |
| CVE-2023-34159(opens NVD record) | Critical | 9.8 | Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality. | Jun 19, 2023 |
| CVE-2023-34158(opens NVD record) | Medium | 5.3 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | Jun 19, 2023 |
| CVE-2023-34156(opens NVD record) | Medium | 5.3 | Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied. | Jun 19, 2023 |
| CVE-2023-34155(opens NVD record) | High | 7.5 | Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this vulnerability may affect availability. | Jun 19, 2023 |
| CVE-2022-48501(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48500(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48499(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48498(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48497(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48496(opens NVD record) | High | 7.5 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | Jun 19, 2023 |
| CVE-2022-48495(opens NVD record) | Medium | 5.3 | Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained. | Jun 19, 2023 |
| CVE-2022-48494(opens NVD record) | High | 7.5 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | Jun 19, 2023 |
| CVE-2022-48493(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48492(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48491(opens NVD record) | Medium | 5.3 | Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time. | Jun 19, 2023 |
| CVE-2022-48490(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48489(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48488(opens NVD record) | Medium | 5.3 | Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop. | Jun 19, 2023 |
| CVE-2022-48487(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2022-48486(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | Jun 19, 2023 |
| CVE-2023-29546(opens NVD record) | Medium | 6.5 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112. | Jun 19, 2023 |
| CVE-2023-29542(opens NVD record) | Critical | 9.8 | A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10. | Jun 19, 2023 |
| CVE-2023-29534(opens NVD record) | Critical | 9.1 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112. | Jun 19, 2023 |
| CVE-2023-25747(opens NVD record) | High | 7.5 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0. | Jun 19, 2023 |
| CVE-2023-32214(opens NVD record) | High | 7.5 | Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. | Jun 19, 2023 |
| CVE-2023-29532(opens NVD record) | Medium | 5.5 | A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10. | Jun 19, 2023 |
| CVE-2023-35829(opens NVD record) | High | 7.0 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. | Jun 18, 2023 |
| CVE-2023-35828(opens NVD record) | High | 7.0 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c. | Jun 18, 2023 |
| CVE-2023-35826(opens NVD record) | High | 7.0 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c. | Jun 18, 2023 |
| CVE-2023-35823(opens NVD record) | High | 7.0 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. | Jun 18, 2023 |
| CVE-2023-28295(opens NVD record) | High | 7.8 | Microsoft Publisher Remote Code Execution Vulnerability | Jun 17, 2023 |
| CVE-2023-28287(opens NVD record) | High | 7.8 | Microsoft Publisher Remote Code Execution Vulnerability | Jun 17, 2023 |
| CVE-2023-35788(opens NVD record) | High | 7.8 | An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation. | Jun 16, 2023 |
| CVE-2023-33438(opens NVD record) | Medium | 5.4 | A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML. | Jun 16, 2023 |
| CVE-2023-30903(opens NVD record) | Medium | 5.5 | HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. | Jun 16, 2023 |
| CVE-2023-25187(opens NVD record) | Medium | 6.3 | An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give access to BTS, because service user authentication is username/password-based on top of SSH. Nokia factory installed default SSH keys are meant to be changed from operator-specific values during the BTS deployment commissioning phase. However, before the 21B release, BTS commissioning manuals did not provide instructions to change default SSH keys (to BTS operator-specific values). This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform troubleshooting activities. | Jun 16, 2023 |