Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1150/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-33693(opens NVD record) | Medium | 5.5 | A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file. | Jun 5, 2023 |
| CVE-2023-32217(opens NVD record) | Critical | 9.0 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath. | Jun 5, 2023 |
| CVE-2023-32334(opens NVD record) | Low | 3.7 | IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074. | Jun 5, 2023 |
| CVE-2023-27861(opens NVD record) | Medium | 5.9 | IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techniques. IBM X-Force ID: 249208. | Jun 5, 2023 |
| CVE-2023-0041(opens NVD record) | Medium | 6.3 | IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657. | Jun 5, 2023 |
| CVE-2023-27285(opens NVD record) | High | 8.4 | IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248625. | Jun 5, 2023 |
| CVE-2023-22862(opens NVD record) | Medium | 5.9 | IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. | Jun 5, 2023 |
| CVE-2023-33143(opens NVD record) | High | 7.5 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Jun 3, 2023 |
| CVE-2023-29551(opens NVD record) | High | 8.8 | Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29550(opens NVD record) | High | 8.8 | Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29549(opens NVD record) | Medium | 6.5 | Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29548(opens NVD record) | Medium | 6.5 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29544(opens NVD record) | Medium | 6.5 | If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29543(opens NVD record) | High | 8.8 | An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29541(opens NVD record) | High | 8.8 | Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29540(opens NVD record) | Medium | 6.1 | Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29539(opens NVD record) | High | 8.8 | When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29538(opens NVD record) | Medium | 4.3 | Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29537(opens NVD record) | High | 7.5 | Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | Jun 2, 2023 |
| CVE-2023-29536(opens NVD record) | High | 8.8 | An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29535(opens NVD record) | Medium | 6.5 | Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-29533(opens NVD record) | Medium | 4.3 | A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. | Jun 2, 2023 |
| CVE-2023-25738(opens NVD record) | Medium | 6.5 | Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. | Jun 2, 2023 |
| CVE-2023-25734(opens NVD record) | High | 8.1 | After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. | Jun 2, 2023 |
| CVE-2023-34362(opens NVD record) | Critical | 9.8 | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions. | Jun 2, 2023 |
| CVE-2023-29725(opens NVD record) | Medium | 5.5 | The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack. | Jun 2, 2023 |
| CVE-2023-29724(opens NVD record) | High | 7.8 | The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack. | Jun 2, 2023 |
| CVE-2023-28066(opens NVD record) | High | 7.3 | Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the system. | Jun 1, 2023 |
| CVE-2023-28043(opens NVD record) | Medium | 6.5 | Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text. | Jun 1, 2023 |
| CVE-2022-35742(opens NVD record) | High | 7.5 | Microsoft Outlook Denial of Service Vulnerability | Jun 1, 2023 |
| CVE-2023-2977(opens NVD record) | High | 7.1 | A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible. | Jun 1, 2023 |
| CVE-2023-2598(opens NVD record) | High | 7.8 | A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation. | Jun 1, 2023 |
| CVE-2023-23955(opens NVD record) | High | 8.1 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | Jun 1, 2023 |
| CVE-2023-23954(opens NVD record) | Medium | 5.4 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. | Jun 1, 2023 |
| CVE-2023-23953(opens NVD record) | High | 7.8 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. | Jun 1, 2023 |
| CVE-2023-23952(opens NVD record) | Critical | 9.8 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | Jun 1, 2023 |
| CVE-2023-26278(opens NVD record) | High | 8.2 | IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID: 248158. | May 31, 2023 |
| CVE-2022-48502(opens NVD record) | High | 7.1 | An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c. | May 31, 2023 |
| CVE-2023-26277(opens NVD record) | High | 7.8 | IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. IBM X-Force ID: 248156. | May 31, 2023 |
| CVE-2022-35759(opens NVD record) | Medium | 6.5 | Windows Local Security Authority (LSA) Denial of Service Vulnerability | May 31, 2023 |
| CVE-2022-35758(opens NVD record) | Medium | 5.5 | Windows Kernel Memory Information Disclosure Vulnerability | May 31, 2023 |
| CVE-2022-35757(opens NVD record) | High | 7.3 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35756(opens NVD record) | High | 7.8 | Windows Kerberos Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35755(opens NVD record) | High | 7.3 | Windows Print Spooler Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35754(opens NVD record) | Medium | 6.7 | Unified Write Filter Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35753(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | May 31, 2023 |
| CVE-2022-35752(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | May 31, 2023 |
| CVE-2022-35751(opens NVD record) | High | 7.8 | Windows Hyper-V Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35750(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35749(opens NVD record) | High | 7.8 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | May 31, 2023 |