Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1193/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-46501(opens NVD record) | Critical | 9.8 | Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function. | Mar 2, 2023 |
| CVE-2022-35645(opens NVD record) | Medium | 6.4 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230958. | Mar 2, 2023 |
| CVE-2022-38734(opens NVD record) | High | 7.5 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service. | Mar 2, 2023 |
| CVE-2023-25536(opens NVD record) | Medium | 6.7 | Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover. | Mar 2, 2023 |
| CVE-2023-0196(opens NVD record) | Low | 3.3 | NVIDIA CUDA Toolkit SDK contains a bug in cuobjdump, where a local user running the tool against an ill-formed binary may cause a null- pointer dereference, which may result in a limited denial of service. | Mar 2, 2023 |
| CVE-2020-5026(opens NVD record) | Medium | 4.3 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662. | Mar 1, 2023 |
| CVE-2020-5001(opens NVD record) | Medium | 4.3 | IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953. | Mar 1, 2023 |
| CVE-2023-24127(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24126(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24125(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24124(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24123(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24122(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24121(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24120(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24119(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24118(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24117(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24134(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24133(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24132(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24131(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1_5g parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24130(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24129(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2023-24128(opens NVD record) | Medium | 6.5 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet. | Mar 1, 2023 |
| CVE-2022-4901(opens NVD record) | Low | 3.3 | Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim. | Mar 1, 2023 |
| CVE-2022-48310(opens NVD record) | Medium | 5.5 | An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90. | Mar 1, 2023 |
| CVE-2022-48309(opens NVD record) | Medium | 4.3 | A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90. | Mar 1, 2023 |
| CVE-2022-45608(opens NVD record) | High | 8.8 | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker must know the corresponding API's parameter (authority : value). | Mar 1, 2023 |
| CVE-2023-25544(opens NVD record) | High | 7.5 | Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. | Mar 1, 2023 |
| CVE-2023-24567(opens NVD record) | High | 7.5 | Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. | Mar 1, 2023 |
| CVE-2023-26281(opens NVD record) | Medium | 5.9 | IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296. | Mar 1, 2023 |
| CVE-2023-22778(opens NVD record) | Medium | 4.8 | A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | Mar 1, 2023 |
| CVE-2023-22777(opens NVD record) | Medium | 4.9 | An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22776(opens NVD record) | Medium | 4.9 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | Mar 1, 2023 |
| CVE-2023-22775(opens NVD record) | Medium | 6.5 | A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | Mar 1, 2023 |
| CVE-2023-22774(opens NVD record) | High | 7.2 | Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22773(opens NVD record) | High | 7.2 | Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22772(opens NVD record) | Medium | 6.5 | An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22771(opens NVD record) | Medium | 6.8 | An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account | Mar 1, 2023 |
| CVE-2023-22770(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22769(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22768(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22767(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22766(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22765(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22764(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22763(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22762(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Mar 1, 2023 |
| CVE-2023-22761(opens NVD record) | High | 7.2 | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS. | Mar 1, 2023 |