Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1151/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-35748(opens NVD record) | High | 7.5 | HTTP.sys Denial of Service Vulnerability | May 31, 2023 |
| CVE-2022-35747(opens NVD record) | Medium | 5.9 | Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | May 31, 2023 |
| CVE-2022-35746(opens NVD record) | High | 7.8 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | May 31, 2023 |
| CVE-2022-35745(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | May 31, 2023 |
| CVE-2022-35744(opens NVD record) | Critical | 9.8 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | May 31, 2023 |
| CVE-2022-35743(opens NVD record) | High | 7.8 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | May 31, 2023 |
| CVE-2023-30285(opens NVD record) | High | 7.5 | An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser. | May 31, 2023 |
| CVE-2023-25539(opens NVD record) | High | 8.4 | Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity. | May 31, 2023 |
| CVE-2023-23562(opens NVD record) | Medium | 4.3 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | May 31, 2023 |
| CVE-2023-28353(opens NVD record) | High | 8.8 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, enabling a variety of different exploitation paths including code execution. It is also possible for the attacker to chain this vulnerability with others to cause a deployed DLL file to immediately execute as NT AUTHORITY/SYSTEM. | May 31, 2023 |
| CVE-2023-28352(opens NVD record) | High | 7.4 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been enabled. | May 31, 2023 |
| CVE-2023-28351(opens NVD record) | Low | 3.3 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim. | May 31, 2023 |
| CVE-2023-28350(opens NVD record) | Medium | 6.1 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine). | May 31, 2023 |
| CVE-2023-28349(opens NVD record) | High | 8.8 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student Consoles can be compelled to write arbitrary files to arbitrary locations on disk with NT AUTHORITY/SYSTEM level permissions, enabling remote code execution. | May 31, 2023 |
| CVE-2023-28348(opens NVD record) | High | 7.4 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being sent from teachers to students. | May 31, 2023 |
| CVE-2023-28347(opens NVD record) | Critical | 9.6 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner. | May 31, 2023 |
| CVE-2023-28346(opens NVD record) | High | 7.3 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this access. Remote attackers can interact with private pages on the web server, enabling them to perform privileged actions such as logging into the console and changing console settings if they have valid credentials. | May 31, 2023 |
| CVE-2023-28345(opens NVD record) | Medium | 4.6 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web browser, navigate to the affected endpoint and obtain the teacher's password. This enables them to log into the Teacher Console and begin trivially attacking student machines. | May 31, 2023 |
| CVE-2023-28344(opens NVD record) | High | 7.1 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console. | May 31, 2023 |
| CVE-2023-34153(opens NVD record) | High | 7.8 | A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. | May 30, 2023 |
| CVE-2023-34152(opens NVD record) | Critical | 9.8 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | May 30, 2023 |
| CVE-2023-34151(opens NVD record) | Medium | 5.5 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | May 30, 2023 |
| CVE-2023-32342(opens NVD record) | High | 7.5 | IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828. | May 30, 2023 |
| CVE-2023-2953(opens NVD record) | High | 7.5 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | May 30, 2023 |
| CVE-2023-2939(opens NVD record) | High | 7.8 | Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) | May 30, 2023 |
| CVE-2023-23956(opens NVD record) | Medium | 5.4 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | May 30, 2023 |
| CVE-2023-23561(opens NVD record) | Medium | 5.5 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | May 30, 2023 |
| CVE-2023-32448(opens NVD record) | Medium | 5.5 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems. | May 30, 2023 |
| CVE-2023-28080(opens NVD record) | Medium | 6.7 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | May 30, 2023 |
| CVE-2023-28079(opens NVD record) | High | 7.0 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | May 30, 2023 |
| CVE-2023-24568(opens NVD record) | Medium | 5.0 | Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates. | May 30, 2023 |
| CVE-2023-20884(opens NVD record) | Medium | 6.1 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | May 30, 2023 |
| CVE-2023-2984(opens NVD record) | High | 8.8 | Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | May 30, 2023 |
| CVE-2015-20108(opens NVD record) | Critical | 9.8 | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | May 27, 2023 |
| CVE-2023-2898(opens NVD record) | Medium | 4.7 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. | May 26, 2023 |
| CVE-2023-27311(opens NVD record) | Medium | 5.3 | NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector. | May 26, 2023 |
| CVE-2023-28322(opens NVD record) | Low | 3.7 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST. | May 26, 2023 |
| CVE-2023-28321(opens NVD record) | Medium | 5.9 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`. | May 26, 2023 |
| CVE-2023-28320(opens NVD record) | Medium | 5.9 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave. | May 26, 2023 |
| CVE-2023-28319(opens NVD record) | High | 7.5 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed. | May 26, 2023 |
| CVE-2023-2283(opens NVD record) | Medium | 6.5 | A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK. | May 26, 2023 |
| CVE-2023-20868(opens NVD record) | Medium | 6.1 | NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages. | May 26, 2023 |
| CVE-2023-1981(opens NVD record) | Medium | 5.5 | A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. | May 26, 2023 |
| CVE-2023-1667(opens NVD record) | Medium | 6.5 | A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service. | May 26, 2023 |
| CVE-2023-1664(opens NVD record) | Medium | 6.5 | A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variable is missing/misconfigured, any trustfile may be accepted with the logging information of "Cannot validate client certificate trust: Truststore not available". This may not impact availability as the attacker would have no access to the server, but consumer applications Integrity or Confidentiality may be impacted considering a possible access to them. Considering the environment is correctly set to use "Revalidate Client Certificate" this flaw is avoidable. | May 26, 2023 |
| CVE-2023-33779(opens NVD record) | High | 8.8 | A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/. | May 26, 2023 |
| CVE-2023-31227(opens NVD record) | High | 7.5 | The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality. | May 26, 2023 |
| CVE-2023-31226(opens NVD record) | High | 7.5 | The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confidentiality. | May 26, 2023 |
| CVE-2023-31225(opens NVD record) | Low | 3.3 | The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability. | May 26, 2023 |
| CVE-2023-20883(opens NVD record) | High | 7.5 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. | May 26, 2023 |