Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1182/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-24885(opens NVD record) | High | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-24884(opens NVD record) | High | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-24883(opens NVD record) | Medium | 6.5 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Apr 11, 2023 |
| CVE-2023-24860(opens NVD record) | High | 7.5 | Microsoft Defender Denial of Service Vulnerability | Apr 11, 2023 |
| CVE-2023-23384(opens NVD record) | High | 7.3 | Microsoft SQL Server Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-23375(opens NVD record) | High | 7.8 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-21769(opens NVD record) | High | 7.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Apr 11, 2023 |
| CVE-2023-21729(opens NVD record) | Medium | 4.3 | Remote Procedure Call Runtime Information Disclosure Vulnerability | Apr 11, 2023 |
| CVE-2023-21727(opens NVD record) | High | 8.8 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-21554(opens NVD record) | Critical | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Apr 11, 2023 |
| CVE-2023-1989(opens NVD record) | High | 7.0 | A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices. | Apr 11, 2023 |
| CVE-2023-27995(opens NVD record) | High | 7.2 | A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload. | Apr 11, 2023 |
| CVE-2023-22642(opens NVD record) | High | 7.5 | An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources. | Apr 11, 2023 |
| CVE-2023-22641(opens NVD record) | Medium | 4.1 | A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specially crafted requests. | Apr 11, 2023 |
| CVE-2023-22635(opens NVD record) | High | 7.3 | A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local attacker to escalate their privileges via modifying the installer upon upgrade. | Apr 11, 2023 |
| CVE-2022-43955(opens NVD record) | High | 8.8 | An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report. | Apr 11, 2023 |
| CVE-2022-43952(opens NVD record) | Low | 3.5 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests. | Apr 11, 2023 |
| CVE-2022-43951(opens NVD record) | Medium | 5.3 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. | Apr 11, 2023 |
| CVE-2022-43948(opens NVD record) | Medium | 6.7 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiADC version 7.1.0 through 7.1.1, FortiADC version 7.0.0 through 7.0.3, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions allows attacker to execute unauthorized code or commands via specifically crafted arguments to existing commands. | Apr 11, 2023 |
| CVE-2022-43947(opens NVD record) | Medium | 5.0 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions. | Apr 11, 2023 |
| CVE-2022-43946(opens NVD record) | High | 7.5 | Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe. | Apr 11, 2023 |
| CVE-2022-42477(opens NVD record) | High | 7.1 | An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries. | Apr 11, 2023 |
| CVE-2022-42470(opens NVD record) | High | 7.8 | A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | Apr 11, 2023 |
| CVE-2022-42469(opens NVD record) | Medium | 4.3 | A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal. | Apr 11, 2023 |
| CVE-2022-41331(opens NVD record) | Critical | 9.8 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. | Apr 11, 2023 |
| CVE-2022-41330(opens NVD record) | High | 8.8 | An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests. | Apr 11, 2023 |
| CVE-2022-40682(opens NVD record) | High | 7.8 | A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | Apr 11, 2023 |
| CVE-2022-40679(opens NVD record) | High | 7.8 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | Apr 11, 2023 |
| CVE-2022-35850(opens NVD record) | Medium | 4.3 | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page. | Apr 11, 2023 |
| CVE-2022-27487(opens NVD record) | High | 8.8 | A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests. | Apr 11, 2023 |
| CVE-2022-27485(opens NVD record) | Medium | 6.5 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read permission to retrieve arbitrary files from the underlying Linux system via a crafted HTTP request. | Apr 11, 2023 |
| CVE-2023-28062(opens NVD record) | High | 8.8 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions. | Apr 11, 2023 |
| CVE-2023-25950(opens NVD record) | High | 7.3 | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition. | Apr 11, 2023 |
| CVE-2023-22282(opens NVD record) | High | 7.3 | WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service. | Apr 11, 2023 |
| CVE-2023-27497(opens NVD record) | Critical | 10.0 | Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system. | Apr 11, 2023 |
| CVE-2023-28341(opens NVD record) | Medium | 6.1 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | Apr 11, 2023 |
| CVE-2023-28340(opens NVD record) | Medium | 6.5 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | Apr 11, 2023 |
| CVE-2022-38604(opens NVD record) | High | 7.3 | Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability. | Apr 11, 2023 |
| CVE-2023-24721(opens NVD record) | Medium | 5.4 | A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML. | Apr 10, 2023 |
| CVE-2023-1668(opens NVD record) | High | 8.2 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow. | Apr 10, 2023 |
| CVE-2018-25084(opens NVD record) | Low | 3.5 | A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.1.3 is able to address this issue. The patch is identified as f64b10d63bb19ca2228b0c2d561a1a6e5a3bf251. It is recommended to upgrade the affected component. VDB-225362 is the identifier assigned to this vulnerability. | Apr 10, 2023 |
| CVE-2023-29376(opens NVD record) | Medium | 5.4 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries. | Apr 10, 2023 |
| CVE-2023-29375(opens NVD record) | Critical | 9.8 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector. | Apr 10, 2023 |
| CVE-2023-27730(opens NVD record) | High | 7.5 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | Apr 9, 2023 |
| CVE-2023-27729(opens NVD record) | High | 7.5 | Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. | Apr 9, 2023 |
| CVE-2023-27728(opens NVD record) | High | 7.5 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | Apr 9, 2023 |
| CVE-2023-27727(opens NVD record) | High | 7.5 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | Apr 9, 2023 |
| CVE-2022-43309(opens NVD record) | Medium | 5.5 | Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions. | Apr 7, 2023 |
| CVE-2023-27876(opens NVD record) | High | 7.1 | IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975. | Apr 7, 2023 |
| CVE-2022-43928(opens NVD record) | Medium | 4.9 | The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this issue by reducing the amount of time the sensitive data is visible in memory. IBM X-Force ID: 241675. | Apr 7, 2023 |