Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,988 matching · page 1155/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-24953(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24950(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Spoofing Vulnerability | May 9, 2023 |
| CVE-2023-24949(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24948(opens NVD record) | High | 7.4 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24947(opens NVD record) | High | 8.8 | Windows Bluetooth Driver Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24946(opens NVD record) | High | 7.8 | Windows Backup Service Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24945(opens NVD record) | Medium | 5.5 | Windows iSCSI Target Service Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24944(opens NVD record) | Medium | 6.5 | Windows Bluetooth Driver Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24943(opens NVD record) | Critical | 9.8 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24942(opens NVD record) | High | 7.5 | Remote Procedure Call Runtime Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24941(opens NVD record) | Critical | 9.8 | Windows Network File System Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24940(opens NVD record) | High | 7.5 | Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24939(opens NVD record) | High | 7.5 | Server for NFS Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24932(opens NVD record) | Medium | 6.7 | Secure Boot Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-24905(opens NVD record) | High | 7.8 | Remote Desktop Client Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24904(opens NVD record) | High | 7.1 | Windows Installer Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24903(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24902(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24901(opens NVD record) | High | 7.5 | Windows NFS Portmapper Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24900(opens NVD record) | Medium | 5.9 | Windows NTLM Security Support Provider Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24899(opens NVD record) | High | 7.0 | Windows Graphics Component Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24898(opens NVD record) | High | 7.5 | Windows SMB Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-20098(opens NVD record) | Medium | 4.4 | A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root. | May 9, 2023 |
| CVE-2023-20046(opens NVD record) | High | 8.8 | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability. | May 9, 2023 |
| CVE-2023-31807(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function. | May 9, 2023 |
| CVE-2023-31806(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function. | May 9, 2023 |
| CVE-2023-31805(opens NVD record) | Medium | 4.8 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function. | May 9, 2023 |
| CVE-2023-31804(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters. | May 9, 2023 |
| CVE-2023-31803(opens NVD record) | Medium | 4.8 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters. | May 9, 2023 |
| CVE-2023-31802(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters. | May 9, 2023 |
| CVE-2023-31801(opens NVD record) | Medium | 6.1 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter. | May 9, 2023 |
| CVE-2023-31800(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter. | May 9, 2023 |
| CVE-2023-31799(opens NVD record) | Medium | 4.8 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter. | May 9, 2023 |
| CVE-2023-30086(opens NVD record) | Medium | 5.5 | Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c. | May 9, 2023 |
| CVE-2023-30237(opens NVD record) | High | 7.8 | CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe. | May 9, 2023 |
| CVE-2021-44283(opens NVD record) | High | 7.5 | A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system. | May 9, 2023 |
| CVE-2023-2513(opens NVD record) | Medium | 6.7 | A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors. | May 8, 2023 |
| CVE-2023-32233(opens NVD record) | High | 7.8 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled. | May 8, 2023 |
| CVE-2023-22791(opens NVD record) | Medium | 5.4 | A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker. | May 8, 2023 |
| CVE-2023-22790(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22789(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22788(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22787(opens NVD record) | High | 7.5 | An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | May 8, 2023 |
| CVE-2023-22786(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22785(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22784(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22783(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22782(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22781(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |
| CVE-2023-22780(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 8, 2023 |