Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1152/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-0117(opens NVD record) | Medium | 5.3 | The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime. | May 26, 2023 |
| CVE-2023-0116(opens NVD record) | High | 7.5 | The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2022-48480(opens NVD record) | High | 7.5 | Integer overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality. | May 26, 2023 |
| CVE-2022-48479(opens NVD record) | Critical | 9.8 | The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | May 26, 2023 |
| CVE-2022-48478(opens NVD record) | Critical | 9.8 | The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | May 26, 2023 |
| CVE-2021-46887(opens NVD record) | Critical | 9.8 | Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read. | May 26, 2023 |
| CVE-2021-46886(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2021-46885(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2021-46884(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2021-46883(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2021-46882(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2021-46881(opens NVD record) | High | 7.5 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | May 26, 2023 |
| CVE-2023-31594(opens NVD record) | High | 7.5 | IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network. | May 25, 2023 |
| CVE-2023-31595(opens NVD record) | High | 7.5 | IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access. | May 24, 2023 |
| CVE-2023-2874(opens NVD record) | Medium | 5.5 | A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the function 0x804f2158/0x804f2154/0x804f2150/0x804f215c/0x804f2160/0x80800040/0x804f214c/0x804f2148/0x804f2144/0x801120e4/0x804f213c/0x804f2140 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-229853 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | May 24, 2023 |
| CVE-2023-2868(opens NVD record) | Critical | 9.4 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances. | May 24, 2023 |
| CVE-2023-2873(opens NVD record) | Medium | 5.3 | A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229852. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | May 24, 2023 |
| CVE-2023-31748(opens NVD record) | High | 7.8 | Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file. | May 24, 2023 |
| CVE-2023-31747(opens NVD record) | High | 7.8 | Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges. | May 23, 2023 |
| CVE-2023-31517(opens NVD record) | High | 7.5 | A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file. | May 23, 2023 |
| CVE-2023-30440(opens NVD record) | Medium | 6.7 | IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175. | May 23, 2023 |
| CVE-2023-23694(opens NVD record) | Medium | 4.7 | Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. | May 23, 2023 |
| CVE-2023-23693(opens NVD record) | Medium | 6.7 | Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. | May 23, 2023 |
| CVE-2023-31741(opens NVD record) | High | 7.2 | There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges. | May 23, 2023 |
| CVE-2023-31740(opens NVD record) | High | 7.2 | There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges. | May 23, 2023 |
| CVE-2023-31664(opens NVD record) | Medium | 6.1 | A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter. | May 23, 2023 |
| CVE-2023-31742(opens NVD record) | High | 7.2 | There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges. | May 22, 2023 |
| CVE-2023-28709(opens NVD record) | High | 7.5 | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur. | May 22, 2023 |
| CVE-2023-25537(opens NVD record) | Medium | 6.1 | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege. | May 22, 2023 |
| CVE-2023-32336(opens NVD record) | High | 8.8 | IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. | May 22, 2023 |
| CVE-2023-33254(opens NVD record) | Medium | 6.5 | There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials. | May 21, 2023 |
| CVE-2023-33250(opens NVD record) | Medium | 4.4 | The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c. | May 21, 2023 |
| CVE-2023-1696(opens NVD record) | High | 7.5 | The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability. | May 20, 2023 |
| CVE-2023-1694(opens NVD record) | High | 7.5 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. | May 20, 2023 |
| CVE-2023-1693(opens NVD record) | High | 7.5 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. | May 20, 2023 |
| CVE-2023-1692(opens NVD record) | High | 7.5 | The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality. | May 20, 2023 |
| CVE-2023-28950(opens NVD record) | Medium | 5.1 | IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled. IBM X-Force ID: 251358. | May 19, 2023 |
| CVE-2023-28529(opens NVD record) | Medium | 5.5 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251213. | May 19, 2023 |
| CVE-2023-22878(opens NVD record) | Medium | 6.2 | IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373. | May 19, 2023 |
| CVE-2022-47984(opens NVD record) | Medium | 6.3 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. | May 19, 2023 |
| CVE-2023-28514(opens NVD record) | Medium | 6.2 | IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398. | May 19, 2023 |
| CVE-2023-26818(opens NVD record) | Medium | 5.5 | Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag. | May 19, 2023 |
| CVE-2023-28045(opens NVD record) | Medium | 6.3 | Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data. | May 19, 2023 |
| CVE-2023-33240(opens NVD record) | High | 7.8 | Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2. | May 19, 2023 |
| CVE-2022-35798(opens NVD record) | Low | 3.3 | Azure Arc Jumpstart Information Disclosure Vulnerability | May 18, 2023 |
| CVE-2022-4418(opens NVD record) | High | 7.8 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208. | May 18, 2023 |
| CVE-2022-45459(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984. | May 18, 2023 |
| CVE-2022-45458(opens NVD record) | High | 7.5 | Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984. | May 18, 2023 |
| CVE-2022-45457(opens NVD record) | High | 7.5 | Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984. | May 18, 2023 |
| CVE-2022-45453(opens NVD record) | High | 7.5 | TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. | May 18, 2023 |