Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1149/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-39946(opens NVD record) | High | 7.6 | An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests. | Jun 13, 2023 |
| CVE-2022-33877(opens NVD record) | High | 7.0 | An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder. | Jun 13, 2023 |
| CVE-2023-32674(opens NVD record) | Critical | 9.8 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow. | Jun 12, 2023 |
| CVE-2023-32673(opens NVD record) | Critical | 9.8 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | Jun 12, 2023 |
| CVE-2023-26298(opens NVD record) | High | 8.8 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | Jun 12, 2023 |
| CVE-2023-26297(opens NVD record) | High | 8.8 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | Jun 12, 2023 |
| CVE-2023-26296(opens NVD record) | High | 8.8 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | Jun 12, 2023 |
| CVE-2023-26295(opens NVD record) | Critical | 9.8 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | Jun 12, 2023 |
| CVE-2023-26294(opens NVD record) | High | 7.8 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | Jun 12, 2023 |
| CVE-2023-3161(opens NVD record) | Medium | 5.5 | A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service. | Jun 12, 2023 |
| CVE-2022-43778(opens NVD record) | High | 7.8 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | Jun 12, 2023 |
| CVE-2022-43777(opens NVD record) | High | 7.8 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | Jun 12, 2023 |
| CVE-2022-27541(opens NVD record) | High | 7.8 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | Jun 12, 2023 |
| CVE-2022-27539(opens NVD record) | High | 7.8 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | Jun 12, 2023 |
| CVE-2023-35036(opens NVD record) | Critical | 9.1 | In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. | Jun 12, 2023 |
| CVE-2023-3141(opens NVD record) | High | 7.1 | A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | Jun 9, 2023 |
| CVE-2023-2455(opens NVD record) | Medium | 5.4 | Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. | Jun 9, 2023 |
| CVE-2023-2454(opens NVD record) | High | 7.2 | schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. | Jun 9, 2023 |
| CVE-2019-16283(opens NVD record) | High | 7.8 | A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution. | Jun 9, 2023 |
| CVE-2023-34364(opens NVD record) | Critical | 9.8 | A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying carefully selected data that will be executed as code. | Jun 9, 2023 |
| CVE-2023-34363(opens NVD record) | Medium | 5.9 | An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random number generator to generate the private key. It is possible for a well-placed attacker to predict the output of this random number generator, which could lead to an attacker decrypting traffic between the driver and the database server. The vulnerability does not exist if SSL / TLS encryption is used. | Jun 9, 2023 |
| CVE-2023-23482(opens NVD record) | Medium | 5.4 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 245891. | Jun 8, 2023 |
| CVE-2023-23481(opens NVD record) | Medium | 6.4 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889. | Jun 8, 2023 |
| CVE-2023-23480(opens NVD record) | Medium | 5.4 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245885. | Jun 8, 2023 |
| CVE-2023-33847(opens NVD record) | Low | 3.7 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257102. | Jun 8, 2023 |
| CVE-2023-33846(opens NVD record) | Medium | 5.4 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 257100. | Jun 8, 2023 |
| CVE-2023-33849(opens NVD record) | Low | 3.7 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105. | Jun 7, 2023 |
| CVE-2023-33848(opens NVD record) | Medium | 4.9 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104. | Jun 7, 2023 |
| CVE-2023-29345(opens NVD record) | Medium | 6.1 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Jun 7, 2023 |
| CVE-2023-20889(opens NVD record) | High | 7.5 | Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure. | Jun 7, 2023 |
| CVE-2023-20888(opens NVD record) | High | 8.8 | Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution. | Jun 7, 2023 |
| CVE-2023-20887(opens NVD record) | Critical | 9.8 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | Jun 7, 2023 |
| CVE-2022-31693(opens NVD record) | Medium | 5.5 | VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS. | Jun 7, 2023 |
| CVE-2023-1388(opens NVD record) | Medium | 6.3 | A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming unavailable. | Jun 7, 2023 |
| CVE-2023-0976(opens NVD record) | Medium | 6.3 | A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious file is executed by running the TA deployment feature located in the System Tree. | Jun 7, 2023 |
| CVE-2023-33782(opens NVD record) | High | 8.8 | D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function. | Jun 7, 2023 |
| CVE-2023-33781(opens NVD record) | High | 8.8 | An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file. | Jun 7, 2023 |
| CVE-2023-2603(opens NVD record) | High | 7.8 | A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. | Jun 6, 2023 |
| CVE-2023-2602(opens NVD record) | Low | 3.3 | A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory. | Jun 6, 2023 |
| CVE-2023-2253(opens NVD record) | Medium | 6.5 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory. | Jun 6, 2023 |
| CVE-2023-27126(opens NVD record) | Medium | 4.6 | The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim. | Jun 6, 2023 |
| CVE-2023-33532(opens NVD record) | Critical | 9.8 | There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges. | Jun 6, 2023 |
| CVE-2023-31569(opens NVD record) | Critical | 9.8 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. | Jun 6, 2023 |
| CVE-2023-33530(opens NVD record) | High | 8.8 | There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges. | Jun 6, 2023 |
| CVE-2023-33381(opens NVD record) | High | 7.2 | A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function. | Jun 6, 2023 |
| CVE-2023-3079(opens NVD record) | High | 8.8 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | Jun 5, 2023 |
| CVE-2023-3027(opens NVD record) | High | 7.8 | The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created. | Jun 5, 2023 |
| CVE-2023-24510(opens NVD record) | High | 7.5 | On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. | Jun 5, 2023 |
| CVE-2023-3111(opens NVD record) | High | 7.8 | A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | Jun 5, 2023 |
| CVE-2023-29344(opens NVD record) | High | 7.8 | Microsoft Office Remote Code Execution Vulnerability | Jun 5, 2023 |