Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1146/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-3268(opens NVD record) | High | 7.1 | An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information. | Jun 16, 2023 |
| CVE-2023-25188(opens NVD record) | Medium | 5.1 | An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level. | Jun 16, 2023 |
| CVE-2023-25186(opens NVD record) | Medium | 5.1 | An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to the BTS baseband unit internal filesystem from the mobile network solution internal BTS management network. | Jun 16, 2023 |
| CVE-2023-25185(opens NVD record) | Low | 3.8 | An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources. | Jun 16, 2023 |
| CVE-2023-34832(opens NVD record) | Critical | 9.8 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | Jun 16, 2023 |
| CVE-2022-48473(opens NVD record) | High | 7.5 | There is a misinterpretation of input vulnerability in Huawei Printer. Successful exploitation of this vulnerability may cause the printer service to be abnormal. | Jun 16, 2023 |
| CVE-2022-48472(opens NVD record) | Critical | 9.8 | A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211. | Jun 16, 2023 |
| CVE-2022-48471(opens NVD record) | High | 7.5 | There is a misinterpretation of input vulnerability in Huawei Printer. Successful exploitation of this vulnerability may cause the printer service to be abnormal. | Jun 16, 2023 |
| CVE-2022-48469(opens NVD record) | Medium | 6.5 | There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. | Jun 16, 2023 |
| CVE-2022-48330(opens NVD record) | High | 8.0 | A Huawei sound box product has an out-of-bounds write vulnerability. Attackers can exploit this vulnerability to cause buffer overflow. Affected product versions include:FLMG-10 versions FLMG-10 10.0.1.0(H100SP22C00). | Jun 16, 2023 |
| CVE-2023-33307(opens NVD record) | Medium | 6.5 | A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | Jun 16, 2023 |
| CVE-2023-33306(opens NVD record) | Medium | 6.5 | A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. | Jun 16, 2023 |
| CVE-2023-34165(opens NVD record) | Medium | 5.3 | Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions. | Jun 16, 2023 |
| CVE-2023-34157(opens NVD record) | Critical | 10.0 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | Jun 16, 2023 |
| CVE-2023-34154(opens NVD record) | High | 8.2 | Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources. | Jun 16, 2023 |
| CVE-2023-35708(opens NVD record) | Critical | 9.8 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3). | Jun 16, 2023 |
| CVE-2023-32028(opens NVD record) | High | 7.8 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-32027(opens NVD record) | High | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-32026(opens NVD record) | High | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-32025(opens NVD record) | High | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-29356(opens NVD record) | High | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-29349(opens NVD record) | High | 7.8 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Jun 16, 2023 |
| CVE-2023-2080(opens NVD record) | High | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection. | Jun 15, 2023 |
| CVE-2023-23841(opens NVD record) | High | 7.5 | SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data. | Jun 15, 2023 |
| CVE-2022-4149(opens NVD record) | High | 7.0 | The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created and written with a SYSTEM account except one file (logplaceholder) which inherits permission giving all users full access control list. Netskope client restricts access to this file by allowing only read permissions as a standard user. Whenever the Netskope client service restarts, it deletes the logplaceholder and recreates, creating a race condition, which can be exploited by a malicious local user to create the file and set ACL permissions on the file. Once the file is created by a malicious user with proper ACL permissions, all files within C:\Users\Public\netSkope\ becomes modifiable by the unprivileged user. By using Windows pseudo-symlink, these files can be pointed to other places in the system and thus malicious users will be able to elevate privileges. | Jun 15, 2023 |
| CVE-2023-2270(opens NVD record) | High | 7.0 | The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope client before R100 in this service utilized a relative path to download and unzip configuration files on the machine. This relative path provided a way for local users to write arbitrary files at a location which is accessible to only higher privileged users. This can be exploited by local users to execute code with NT\SYSTEM privileges on the end machine. | Jun 15, 2023 |
| CVE-2022-33166(opens NVD record) | High | 7.2 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586. | Jun 15, 2023 |
| CVE-2022-32757(opens NVD record) | High | 7.5 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510. | Jun 15, 2023 |
| CVE-2022-32752(opens NVD record) | High | 7.2 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 228439. | Jun 15, 2023 |
| CVE-2022-33168(opens NVD record) | High | 7.5 | IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588. | Jun 15, 2023 |
| CVE-2022-33163(opens NVD record) | Medium | 5.3 | IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 228571. | Jun 15, 2023 |
| CVE-2022-33159(opens NVD record) | Medium | 5.3 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 228567. | Jun 15, 2023 |
| CVE-2023-25683(opens NVD record) | Medium | 5.9 | IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could allow an attacker to obtain sensitive information if they gain service access to the HMC. IBM X-Force ID: 247592. | Jun 15, 2023 |
| CVE-2022-22307(opens NVD record) | Medium | 4.4 | IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. | Jun 15, 2023 |
| CVE-2023-1329(opens NVD record) | Critical | 9.8 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | Jun 14, 2023 |
| CVE-2023-34367(opens NVD record) | Medium | 6.5 | Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor considers this a low severity issue. | Jun 14, 2023 |
| CVE-2023-26062(opens NVD record) | High | 7.0 | A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that exploit is not possible from mobile network user UEs, from roaming networks, or from the Internet. Exploitation is possible only from a CSP (Communication Service Provider) mobile network solution internal BTS management network. | Jun 14, 2023 |
| CVE-2022-31646(opens NVD record) | High | 7.8 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2022-31645(opens NVD record) | High | 7.8 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2022-31644(opens NVD record) | High | 7.8 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2023-0010(opens NVD record) | Medium | 5.4 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link. | Jun 14, 2023 |
| CVE-2023-0009(opens NVD record) | High | 7.8 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges. | Jun 14, 2023 |
| CVE-2022-31642(opens NVD record) | High | 7.0 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2022-31641(opens NVD record) | High | 7.0 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2022-31640(opens NVD record) | High | 7.0 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 14, 2023 |
| CVE-2023-32031(opens NVD record) | High | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | Jun 14, 2023 |
| CVE-2023-32030(opens NVD record) | High | 7.5 | .NET and Visual Studio Denial of Service Vulnerability | Jun 14, 2023 |
| CVE-2023-32024(opens NVD record) | Low | 3.0 | Microsoft Power Apps Spoofing Vulnerability | Jun 14, 2023 |
| CVE-2023-29337(opens NVD record) | High | 7.1 | NuGet Client Remote Code Execution Vulnerability | Jun 14, 2023 |
| CVE-2023-29331(opens NVD record) | High | 7.5 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Jun 14, 2023 |