Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1191/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-23404(opens NVD record) | High | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23403(opens NVD record) | High | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23402(opens NVD record) | High | 7.8 | Windows Media Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23401(opens NVD record) | High | 7.8 | Windows Media Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23400(opens NVD record) | High | 7.2 | Windows DNS Server Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23399(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23398(opens NVD record) | High | 7.1 | Microsoft Excel Spoofing Vulnerability | Mar 14, 2023 |
| CVE-2023-23397(opens NVD record) | Critical | 9.8 | Microsoft Outlook Elevation of Privilege Vulnerability | Mar 14, 2023 |
| CVE-2023-23396(opens NVD record) | Medium | 6.5 | Microsoft Excel Denial of Service Vulnerability | Mar 14, 2023 |
| CVE-2023-23395(opens NVD record) | Low | 3.1 | Microsoft SharePoint Server Spoofing Vulnerability | Mar 14, 2023 |
| CVE-2023-23394(opens NVD record) | Medium | 5.5 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | Mar 14, 2023 |
| CVE-2023-23393(opens NVD record) | High | 7.0 | Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | Mar 14, 2023 |
| CVE-2023-23392(opens NVD record) | Critical | 9.8 | HTTP Protocol Stack Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-23391(opens NVD record) | Medium | 5.5 | Office for Android Spoofing Vulnerability | Mar 14, 2023 |
| CVE-2023-23389(opens NVD record) | Medium | 6.3 | Microsoft Defender Elevation of Privilege Vulnerability | Mar 14, 2023 |
| CVE-2023-23388(opens NVD record) | High | 8.8 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Mar 14, 2023 |
| CVE-2023-23385(opens NVD record) | High | 7.0 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | Mar 14, 2023 |
| CVE-2023-23383(opens NVD record) | High | 8.2 | Service Fabric Explorer Spoofing Vulnerability | Mar 14, 2023 |
| CVE-2023-21708(opens NVD record) | Critical | 9.8 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Mar 14, 2023 |
| CVE-2023-0978(opens NVD record) | Medium | 6.4 | A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack | Mar 13, 2023 |
| CVE-2023-24579(opens NVD record) | Medium | 5.5 | McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt. | Mar 13, 2023 |
| CVE-2023-24578(opens NVD record) | Medium | 5.5 | McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks. | Mar 13, 2023 |
| CVE-2023-24577(opens NVD record) | Medium | 5.5 | McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks. | Mar 13, 2023 |
| CVE-2023-23328(opens NVD record) | High | 8.8 | A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file. | Mar 10, 2023 |
| CVE-2023-23327(opens NVD record) | Medium | 4.9 | An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls. | Mar 10, 2023 |
| CVE-2023-23326(opens NVD record) | Medium | 5.4 | A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session. | Mar 10, 2023 |
| CVE-2022-44574(opens NVD record) | High | 7.5 | An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | Mar 10, 2023 |
| CVE-2023-25148(opens NVD record) | High | 7.8 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Mar 10, 2023 |
| CVE-2023-25147(opens NVD record) | Medium | 6.7 | An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this. | Mar 10, 2023 |
| CVE-2023-25146(opens NVD record) | High | 7.8 | A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Mar 10, 2023 |
| CVE-2023-25145(opens NVD record) | High | 7.8 | A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Mar 10, 2023 |
| CVE-2023-25144(opens NVD record) | High | 7.8 | An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. | Mar 10, 2023 |
| CVE-2023-25143(opens NVD record) | Critical | 9.8 | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | Mar 10, 2023 |
| CVE-2023-24975(opens NVD record) | Medium | 5.4 | IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 247030. | Mar 10, 2023 |
| CVE-2023-0193(opens NVD record) | Medium | 4.4 | NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious binary may cause an out-of-bounds read, which may result in a limited denial of service and limited information disclosure. | Mar 10, 2023 |
| CVE-2022-43902(opens NVD record) | Medium | 6.5 | IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832. | Mar 10, 2023 |
| CVE-2022-20929(opens NVD record) | High | 7.8 | A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker could exploit this vulnerability by providing an administrator with an unauthentic upgrade file. A successful exploit could allow the attacker to fully compromise the Cisco NFVIS system. | Mar 10, 2023 |
| CVE-2020-5002(opens NVD record) | Medium | 4.3 | IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954. | Mar 10, 2023 |
| CVE-2023-27164(opens NVD record) | Medium | 4.8 | An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file. | Mar 10, 2023 |
| CVE-2023-27161(opens NVD record) | High | 7.5 | Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request. | Mar 10, 2023 |
| CVE-2022-48111(opens NVD record) | Medium | 6.1 | A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter. | Mar 10, 2023 |
| CVE-2023-20064(opens NVD record) | Medium | 4.6 | A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB environment that allow sensitive files to be viewed. An attacker could exploit this vulnerability by being connected to the console port of the Cisco IOS XR device when the device is power-cycled. A successful exploit could allow the attacker to view sensitive files that could be used to conduct additional attacks against the device. | Mar 9, 2023 |
| CVE-2023-20049(opens NVD record) | High | 8.6 | A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of malformed BFD packets that are received on line cards where the BFD hardware offload feature is enabled. An attacker could exploit this vulnerability by sending a crafted IPv4 BFD packet to an affected device. A successful exploit could allow the attacker to cause line card exceptions or a hard reset, resulting in loss of traffic over that line card while the line card reloads. | Mar 9, 2023 |
| CVE-2023-27206(opens NVD record) | Medium | 6.1 | A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter. | Mar 9, 2023 |
| CVE-2023-27205(opens NVD record) | Critical | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php. | Mar 9, 2023 |
| CVE-2023-27204(opens NVD record) | Critical | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | Mar 9, 2023 |
| CVE-2023-27203(opens NVD record) | Critical | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | Mar 9, 2023 |
| CVE-2023-27202(opens NVD record) | Critical | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php. | Mar 9, 2023 |
| CVE-2023-26209(opens NVD record) | Low | 3.7 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. | Mar 9, 2023 |
| CVE-2023-26208(opens NVD record) | Low | 3.7 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. | Mar 9, 2023 |