Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1171/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-28128(opens NVD record) | High | 7.2 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | May 9, 2023 |
| CVE-2023-28127(opens NVD record) | High | 7.5 | A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure. | May 9, 2023 |
| CVE-2023-28126(opens NVD record) | Medium | 5.9 | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message. | May 9, 2023 |
| CVE-2023-28125(opens NVD record) | Medium | 5.9 | An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass. | May 9, 2023 |
| CVE-2023-30057(opens NVD record) | Medium | 5.4 | Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | May 9, 2023 |
| CVE-2023-30056(opens NVD record) | High | 7.5 | A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie. | May 9, 2023 |
| CVE-2023-29343(opens NVD record) | High | 7.8 | SysInternals Sysmon for Windows Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-29341(opens NVD record) | High | 7.8 | AV1 Video Extension Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29340(opens NVD record) | High | 7.8 | AV1 Video Extension Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29338(opens NVD record) | Medium | 6.6 | Visual Studio Code Spoofing Vulnerability | May 9, 2023 |
| CVE-2023-29336(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-29335(opens NVD record) | High | 7.5 | Microsoft Word Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-29333(opens NVD record) | Low | 3.3 | Microsoft Access Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-29325(opens NVD record) | High | 8.1 | Windows OLE Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-29324(opens NVD record) | Medium | 6.5 | Windows MSHTML Platform Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-28290(opens NVD record) | Medium | 5.3 | Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-28283(opens NVD record) | High | 8.1 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-28251(opens NVD record) | Medium | 5.5 | Windows Driver Revocation List Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-24955(opens NVD record) | High | 7.2 | Microsoft SharePoint Server Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24954(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24953(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24950(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Spoofing Vulnerability | May 9, 2023 |
| CVE-2023-24949(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24948(opens NVD record) | High | 7.4 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24947(opens NVD record) | High | 8.8 | Windows Bluetooth Driver Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24946(opens NVD record) | High | 7.8 | Windows Backup Service Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24945(opens NVD record) | Medium | 5.5 | Windows iSCSI Target Service Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24944(opens NVD record) | Medium | 6.5 | Windows Bluetooth Driver Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24943(opens NVD record) | Critical | 9.8 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24942(opens NVD record) | High | 7.5 | Remote Procedure Call Runtime Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24941(opens NVD record) | Critical | 9.8 | Windows Network File System Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24940(opens NVD record) | High | 7.5 | Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24939(opens NVD record) | High | 7.5 | Server for NFS Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-24932(opens NVD record) | Medium | 6.7 | Secure Boot Security Feature Bypass Vulnerability | May 9, 2023 |
| CVE-2023-24905(opens NVD record) | High | 7.8 | Remote Desktop Client Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24904(opens NVD record) | High | 7.1 | Windows Installer Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24903(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | May 9, 2023 |
| CVE-2023-24902(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24901(opens NVD record) | High | 7.5 | Windows NFS Portmapper Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24900(opens NVD record) | Medium | 5.9 | Windows NTLM Security Support Provider Information Disclosure Vulnerability | May 9, 2023 |
| CVE-2023-24899(opens NVD record) | High | 7.0 | Windows Graphics Component Elevation of Privilege Vulnerability | May 9, 2023 |
| CVE-2023-24898(opens NVD record) | High | 7.5 | Windows SMB Denial of Service Vulnerability | May 9, 2023 |
| CVE-2023-20098(opens NVD record) | Medium | 4.4 | A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root. | May 9, 2023 |
| CVE-2023-20046(opens NVD record) | High | 8.8 | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability. | May 9, 2023 |
| CVE-2023-31807(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function. | May 9, 2023 |
| CVE-2023-31806(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function. | May 9, 2023 |
| CVE-2023-31805(opens NVD record) | Medium | 4.8 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function. | May 9, 2023 |
| CVE-2023-31804(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters. | May 9, 2023 |
| CVE-2023-31803(opens NVD record) | Medium | 4.8 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters. | May 9, 2023 |
| CVE-2023-31802(opens NVD record) | Medium | 5.4 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters. | May 9, 2023 |