Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1148/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-29364(opens NVD record) | High | 7.0 | Windows Authentication Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29363(opens NVD record) | Critical | 9.8 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Jun 14, 2023 |
| CVE-2023-29362(opens NVD record) | High | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | Jun 14, 2023 |
| CVE-2023-29361(opens NVD record) | High | 7.0 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29360(opens NVD record) | High | 8.4 | Microsoft Streaming Service Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29359(opens NVD record) | High | 7.8 | GDI Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29358(opens NVD record) | High | 7.8 | Windows GDI Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29357(opens NVD record) | Critical | 9.8 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29355(opens NVD record) | Medium | 5.3 | DHCP Server Service Information Disclosure Vulnerability | Jun 14, 2023 |
| CVE-2023-29353(opens NVD record) | Medium | 5.5 | Sysinternals Process Monitor for Windows Denial of Service Vulnerability | Jun 14, 2023 |
| CVE-2023-29352(opens NVD record) | Medium | 6.5 | Windows Remote Desktop Security Feature Bypass Vulnerability | Jun 14, 2023 |
| CVE-2023-29351(opens NVD record) | High | 8.1 | Windows Group Policy Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-29346(opens NVD record) | High | 7.8 | NTFS Elevation of Privilege Vulnerability | Jun 14, 2023 |
| CVE-2023-24938(opens NVD record) | Medium | 6.5 | Windows CryptoAPI Denial of Service Vulnerability | Jun 14, 2023 |
| CVE-2023-21569(opens NVD record) | Medium | 5.5 | Azure DevOps Server Spoofing Vulnerability | Jun 14, 2023 |
| CVE-2023-21565(opens NVD record) | High | 7.1 | Azure DevOps Server Spoofing Vulnerability | Jun 14, 2023 |
| CVE-2023-24470(opens NVD record) | Critical | 9.1 | Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. | Jun 13, 2023 |
| CVE-2023-24469(opens NVD record) | Medium | 6.1 | Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | Jun 13, 2023 |
| CVE-2023-34944(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file. | Jun 13, 2023 |
| CVE-2023-24546(opens NVD record) | High | 8.1 | On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service. | Jun 13, 2023 |
| CVE-2023-34121(opens NVD record) | Medium | 4.1 | Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. | Jun 13, 2023 |
| CVE-2023-34120(opens NVD record) | High | 8.7 | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. | Jun 13, 2023 |
| CVE-2023-28603(opens NVD record) | High | 7.7 | Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions. | Jun 13, 2023 |
| CVE-2023-1707(opens NVD record) | High | 7.5 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6. | Jun 13, 2023 |
| CVE-2023-33620(opens NVD record) | Medium | 5.9 | GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle attack. | Jun 13, 2023 |
| CVE-2023-31541(opens NVD record) | Critical | 9.8 | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server. | Jun 13, 2023 |
| CVE-2023-28303(opens NVD record) | Low | 3.3 | Windows Snipping Tool Information Disclosure Vulnerability | Jun 13, 2023 |
| CVE-2023-20867(opens NVD record) | Low | 3.9 | A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. | Jun 13, 2023 |
| CVE-2022-31639(opens NVD record) | High | 7.8 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 13, 2023 |
| CVE-2022-31638(opens NVD record) | High | 7.8 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 13, 2023 |
| CVE-2022-31637(opens NVD record) | High | 7.8 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 13, 2023 |
| CVE-2022-31636(opens NVD record) | High | 7.8 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 13, 2023 |
| CVE-2022-31635(opens NVD record) | High | 7.8 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | Jun 13, 2023 |
| CVE-2023-33621(opens NVD record) | Medium | 5.9 | GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay. | Jun 13, 2023 |
| CVE-2023-33305(opens NVD record) | Medium | 4.9 | A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests. | Jun 13, 2023 |
| CVE-2023-29178(opens NVD record) | Medium | 4.3 | A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests. | Jun 13, 2023 |
| CVE-2023-29175(opens NVD record) | Medium | 4.8 | An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server. | Jun 13, 2023 |
| CVE-2023-28000(opens NVD record) | Medium | 6.7 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized commands via specifically crafted arguments in diagnose system df CLI command. | Jun 13, 2023 |
| CVE-2023-27997(opens NVD record) | Critical | 9.8 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. | Jun 13, 2023 |
| CVE-2023-26210(opens NVD record) | High | 7.8 | Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests. | Jun 13, 2023 |
| CVE-2023-26207(opens NVD record) | Low | 3.3 | An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text. | Jun 13, 2023 |
| CVE-2023-26204(opens NVD record) | Low | 3.7 | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI. | Jun 13, 2023 |
| CVE-2023-25609(opens NVD record) | Medium | 4.3 | A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests. | Jun 13, 2023 |
| CVE-2023-22639(opens NVD record) | Medium | 6.7 | A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows attacker to escalation of privilege via specifically crafted commands. | Jun 13, 2023 |
| CVE-2023-22633(opens NVD record) | High | 7.5 | An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attack on the device via client-secure renegotiation. | Jun 13, 2023 |
| CVE-2022-43953(opens NVD record) | Medium | 6.7 | A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands. | Jun 13, 2023 |
| CVE-2022-43949(opens NVD record) | Medium | 6.2 | A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods. | Jun 13, 2023 |
| CVE-2022-42478(opens NVD record) | High | 8.1 | An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints. | Jun 13, 2023 |
| CVE-2022-42474(opens NVD record) | Medium | 6.5 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests. | Jun 13, 2023 |
| CVE-2022-41327(opens NVD record) | High | 7.8 | A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands. | Jun 13, 2023 |