Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1174/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-27556(opens NVD record) | Medium | 6.5 | IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not properly allocate resources without limits or throttling which could allow a remote attacker to cause a denial of service. IBM X-Force ID: 249190. | Apr 28, 2023 |
| CVE-2023-28286(opens NVD record) | Medium | 6.1 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Apr 27, 2023 |
| CVE-2023-28261(opens NVD record) | Medium | 5.7 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 27, 2023 |
| CVE-2023-27860(opens NVD record) | Medium | 5.3 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207. | Apr 27, 2023 |
| CVE-2023-21712(opens NVD record) | High | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Apr 27, 2023 |
| CVE-2023-24966(opens NVD record) | Medium | 6.1 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904. | Apr 27, 2023 |
| CVE-2023-30444(opens NVD record) | High | 7.1 | IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350. | Apr 27, 2023 |
| CVE-2023-29255(opens NVD record) | High | 7.5 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991. | Apr 27, 2023 |
| CVE-2022-47758(opens NVD record) | Critical | 9.8 | Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. | Apr 27, 2023 |
| CVE-2023-25292(opens NVD record) | Medium | 6.1 | Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie. | Apr 27, 2023 |
| CVE-2023-30846(opens NVD record) | Critical | 9.1 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler`. Second, the target host may return a redirection (3xx), with a link to a second host. Third, the next request will use the credentials to authenticate with the second host, by setting the `Authorization` header. The expected behavior is that the next request will *NOT* set the `Authorization` header. The problem was fixed in version 1.8.0. There are no known workarounds. | Apr 26, 2023 |
| CVE-2023-2291(opens NVD record) | High | 7.8 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user. | Apr 26, 2023 |
| CVE-2023-29443(opens NVD record) | Medium | 4.9 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | Apr 26, 2023 |
| CVE-2023-29442(opens NVD record) | Medium | 6.1 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | Apr 26, 2023 |
| CVE-2023-27559(opens NVD record) | Medium | 5.3 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196. | Apr 26, 2023 |
| CVE-2022-45456(opens NVD record) | High | 7.5 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161. | Apr 26, 2023 |
| CVE-2022-27979(opens NVD record) | Medium | 5.4 | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component. | Apr 26, 2023 |
| CVE-2022-27978(opens NVD record) | High | 7.5 | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request. | Apr 26, 2023 |
| CVE-2023-29257(opens NVD record) | High | 7.2 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011. | Apr 26, 2023 |
| CVE-2023-26286(opens NVD record) | High | 8.4 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421. | Apr 26, 2023 |
| CVE-2022-41739(opens NVD record) | High | 7.9 | IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID: 237815. | Apr 26, 2023 |
| CVE-2022-36769(opens NVD record) | High | 7.2 | IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034. | Apr 26, 2023 |
| CVE-2023-30404(opens NVD record) | Critical | 9.8 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | Apr 26, 2023 |
| CVE-2023-26735(opens NVD record) | High | 7.5 | blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured. | Apr 26, 2023 |
| CVE-2023-0045(opens NVD record) | Medium | 4.7 | The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall. The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176. We recommend upgrading past commit a664ec9158eeddd75121d39c9a0758016097fa96 | Apr 25, 2023 |
| CVE-2023-20870(opens NVD record) | Medium | 6.0 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | Apr 25, 2023 |
| CVE-2023-20869(opens NVD record) | High | 8.2 | VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | Apr 25, 2023 |
| CVE-2023-30549(opens NVD record) | High | 7.1 | Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian 10 buster (unless the linux-5.10 package is installed), Ubuntu 18.04 bionic and Ubuntu 20.04 focal. Use-after-free flaws in the kernel can be used to attack the kernel for denial of service and potentially for privilege escalation. Apptainer 1.1.8 includes a patch that by default disables mounting of extfs filesystem types in setuid-root mode, while continuing to allow mounting of extfs filesystems in non-setuid "rootless" mode using fuse2fs. Some workarounds are possible. Either do not install apptainer-suid (for versions 1.1.0 through 1.1.7) or set `allow setuid = no` in apptainer.conf. This requires having unprivileged user namespaces enabled and except for apptainer 1.1.x versions will disallow mounting of sif files, extfs files, and squashfs files in addition to other, less significant impacts. (Encrypted sif files are also not supported unprivileged in apptainer 1.1.x.). Alternatively, use the `limit containers` options in apptainer.conf/singularity.conf to limit sif files to trusted users, groups, and/or paths, and set `allow container extfs = no` to disallow mounting of extfs overlay files. The latter option by itself does not disallow mounting of extfs overlay partitions inside SIF files, so that's why the former options are also needed. | Apr 25, 2023 |
| CVE-2023-2269(opens NVD record) | Medium | 4.4 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. | Apr 25, 2023 |
| CVE-2023-24512(opens NVD record) | High | 8.8 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision | Apr 25, 2023 |
| CVE-2023-23839(opens NVD record) | Medium | 6.5 | The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information. | Apr 25, 2023 |
| CVE-2023-20872(opens NVD record) | High | 8.8 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | Apr 25, 2023 |
| CVE-2023-20871(opens NVD record) | High | 7.8 | VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | Apr 25, 2023 |
| CVE-2023-28084(opens NVD record) | Medium | 5.5 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | Apr 25, 2023 |
| CVE-2023-2282(opens NVD record) | Medium | 6.5 | Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector. | Apr 25, 2023 |
| CVE-2023-28090(opens NVD record) | Medium | 5.5 | An HPE OneView appliance dump may expose SNMPv3 read credentials | Apr 25, 2023 |
| CVE-2023-28089(opens NVD record) | High | 7.1 | An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules | Apr 25, 2023 |
| CVE-2023-28088(opens NVD record) | High | 7.8 | An HPE OneView appliance dump may expose SAN switch administrative credentials | Apr 25, 2023 |
| CVE-2023-28087(opens NVD record) | Medium | 5.5 | An HPE OneView appliance dump may expose OneView user accounts | Apr 25, 2023 |
| CVE-2023-28086(opens NVD record) | Medium | 5.5 | An HPE OneView appliance dump may expose proxy credential settings | Apr 25, 2023 |
| CVE-2022-40725(opens NVD record) | High | 7.3 | PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated. | Apr 25, 2023 |
| CVE-2022-40724(opens NVD record) | Medium | 6.4 | The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests. | Apr 25, 2023 |
| CVE-2022-40723(opens NVD record) | Medium | 6.5 | The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations. | Apr 25, 2023 |
| CVE-2022-40722(opens NVD record) | High | 7.7 | A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA. | Apr 25, 2023 |
| CVE-2022-23721(opens NVD record) | Low | 3.8 | PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times. | Apr 25, 2023 |
| CVE-2023-23838(opens NVD record) | Medium | 6.5 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | Apr 25, 2023 |
| CVE-2023-23837(opens NVD record) | High | 7.5 | No exception handling vulnerability which revealed sensitive or excessive information to users. | Apr 25, 2023 |
| CVE-2023-29552(opens NVD record) | High | 7.5 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. | Apr 25, 2023 |
| CVE-2022-31244(opens NVD record) | High | 7.8 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. | Apr 25, 2023 |
| CVE-2023-26058(opens NVD record) | Medium | 6.5 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user. | Apr 25, 2023 |