Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,953 matching · page 1170/1340Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-25891(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25890(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25889(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25888(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25887(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25886(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25885(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25884(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25883(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25882(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25881(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25880(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2023-25879(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 28, 2023 |
| CVE-2022-24908(opens NVD record) | High | 7.8 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16187. | Mar 28, 2023 |
| CVE-2022-24907(opens NVD record) | High | 7.8 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16186. | Mar 28, 2023 |
| CVE-2023-25260(opens NVD record) | High | 7.5 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. | Mar 28, 2023 |
| CVE-2022-47529(opens NVD record) | Medium | 6.7 | Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification. | Mar 28, 2023 |
| CVE-2023-25262(opens NVD record) | High | 7.5 | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web). | Mar 28, 2023 |
| CVE-2023-26549(opens NVD record) | High | 7.5 | The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2023-26548(opens NVD record) | High | 7.5 | The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability. | Mar 27, 2023 |
| CVE-2023-26547(opens NVD record) | High | 7.8 | The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | Mar 27, 2023 |
| CVE-2023-20860(opens NVD record) | High | 7.5 | Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass. | Mar 27, 2023 |
| CVE-2023-0179(opens NVD record) | High | 7.8 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. | Mar 27, 2023 |
| CVE-2022-48361(opens NVD record) | Medium | 5.3 | The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources. | Mar 27, 2023 |
| CVE-2022-48360(opens NVD record) | High | 7.5 | The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-48359(opens NVD record) | High | 7.5 | The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-48358(opens NVD record) | High | 7.4 | The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions. | Mar 27, 2023 |
| CVE-2022-48357(opens NVD record) | High | 7.5 | Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel. | Mar 27, 2023 |
| CVE-2022-48356(opens NVD record) | High | 7.5 | The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition. | Mar 27, 2023 |
| CVE-2022-48355(opens NVD record) | Medium | 6.5 | The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash. | Mar 27, 2023 |
| CVE-2022-48354(opens NVD record) | Medium | 6.5 | The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash. | Mar 27, 2023 |
| CVE-2022-48353(opens NVD record) | Critical | 9.8 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions. | Mar 27, 2023 |
| CVE-2022-48352(opens NVD record) | High | 7.5 | Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic. | Mar 27, 2023 |
| CVE-2022-48351(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability. | Mar 27, 2023 |
| CVE-2022-48350(opens NVD record) | High | 7.5 | The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-48349(opens NVD record) | Critical | 9.1 | The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability. | Mar 27, 2023 |
| CVE-2022-48348(opens NVD record) | Critical | 9.1 | The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity. | Mar 27, 2023 |
| CVE-2022-48347(opens NVD record) | High | 7.5 | The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-48346(opens NVD record) | High | 7.5 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-48291(opens NVD record) | Medium | 6.5 | The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. | Mar 27, 2023 |
| CVE-2022-2237(opens NVD record) | Medium | 6.1 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. | Mar 27, 2023 |
| CVE-2023-28597(opens NVD record) | High | 8.3 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. | Mar 27, 2023 |
| CVE-2023-25908(opens NVD record) | High | 7.8 | Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25878(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25877(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25876(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25875(opens NVD record) | Medium | 5.5 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25874(opens NVD record) | High | 7.8 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25873(opens NVD record) | High | 7.8 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |
| CVE-2023-25872(opens NVD record) | High | 7.8 | Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 27, 2023 |