Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1154/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-1729(opens NVD record) | Medium | 6.5 | A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. | May 15, 2023 |
| CVE-2023-2088(opens NVD record) | Medium | 6.5 | A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality. | May 12, 2023 |
| CVE-2023-20880(opens NVD record) | Medium | 6.7 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | May 12, 2023 |
| CVE-2023-20879(opens NVD record) | Medium | 6.7 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | May 12, 2023 |
| CVE-2023-20878(opens NVD record) | High | 7.2 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | May 12, 2023 |
| CVE-2023-20877(opens NVD record) | High | 8.8 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | May 12, 2023 |
| CVE-2023-1096(opens NVD record) | Critical | 9.8 | SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user. | May 12, 2023 |
| CVE-2023-27863(opens NVD record) | Medium | 4.4 | IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325. | May 12, 2023 |
| CVE-2023-25927(opens NVD record) | Medium | 6.5 | IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635. | May 12, 2023 |
| CVE-2023-27823(opens NVD record) | Critical | 9.8 | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | May 12, 2023 |
| CVE-2022-47880(opens NVD record) | Medium | 5.3 | An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function. | May 12, 2023 |
| CVE-2022-47879(opens NVD record) | High | 7.5 | A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected. | May 12, 2023 |
| CVE-2023-29820(opens NVD record) | Medium | 5.5 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819. | May 12, 2023 |
| CVE-2023-29819(opens NVD record) | Medium | 5.5 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. | May 12, 2023 |
| CVE-2023-29818(opens NVD record) | Medium | 5.5 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin. | May 12, 2023 |
| CVE-2023-27237(opens NVD record) | Medium | 6.1 | LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. | May 12, 2023 |
| CVE-2023-28522(opens NVD record) | Medium | 4.3 | IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585. | May 12, 2023 |
| CVE-2023-28520(opens NVD record) | Medium | 6.4 | IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454. | May 12, 2023 |
| CVE-2021-39036(opens NVD record) | Medium | 6.1 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966. | May 12, 2023 |
| CVE-2023-27870(opens NVD record) | Medium | 5.9 | IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518. | May 11, 2023 |
| CVE-2023-27554(opens NVD record) | Medium | 6.3 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185. | May 11, 2023 |
| CVE-2023-25309(opens NVD record) | Medium | 6.1 | Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality. | May 11, 2023 |
| CVE-2023-29863(opens NVD record) | Critical | 9.8 | Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files. | May 11, 2023 |
| CVE-2023-0008(opens NVD record) | Medium | 4.4 | A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. | May 10, 2023 |
| CVE-2023-0007(opens NVD record) | Medium | 6.5 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed. | May 10, 2023 |
| CVE-2023-27382(opens NVD record) | Medium | 6.7 | Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access. | May 10, 2023 |
| CVE-2022-41687(opens NVD record) | Medium | 6.7 | Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access. | May 10, 2023 |
| CVE-2022-41628(opens NVD record) | Medium | 6.7 | Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access. | May 10, 2023 |
| CVE-2023-32573(opens NVD record) | Medium | 6.5 | In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled. | May 10, 2023 |
| CVE-2023-2156(opens NVD record) | High | 7.5 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system. | May 9, 2023 |
| CVE-2023-28128(opens NVD record) | High | 7.2 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | May 9, 2023 |
| CVE-2023-28127(opens NVD record) | High | 7.5 | A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure. | May 9, 2023 |
| CVE-2023-28126(opens NVD record) | Medium | 5.9 | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message. | May 9, 2023 |
| CVE-2023-28125(opens NVD record) | Medium | 5.9 | An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass. | May 9, 2023 |
| CVE-2023-30057(opens NVD record) | Medium | 5.4 | Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | May 9, 2023 |
| CVE-2023-30056(opens NVD record) | High | 7.5 | A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie. | May 9, 2023 |
| CVE-2023-29343(opens NVD record) | High | 7.8 | SysInternals Sysmon for Windows Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-29341(opens NVD record) | High | 7.8 | AV1 Video Extension Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29340(opens NVD record) | High | 7.8 | AV1 Video Extension Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29338(opens NVD record) | Medium | 6.6 | Visual Studio Code Spoofing Vulnerability | May 9, 2023 |
| CVE-2023-29336(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-29335(opens NVD record) | High | 7.5 | Microsoft Word Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-29333(opens NVD record) | Low | 3.3 | Microsoft Access Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-29325(opens NVD record) | High | 8.1 | Windows OLE Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29324(opens NVD record) | Medium | 6.5 | Windows MSHTML Platform Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-28290(opens NVD record) | Medium | 5.3 | Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-28283(opens NVD record) | High | 8.1 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-28251(opens NVD record) | Medium | 5.5 | Windows Driver Revocation List Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-24955(opens NVD record) | High | 7.2 | Microsoft SharePoint Server Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24954(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Information Disclosure Vulnerability | May 9, 2023 |