Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,775 matching · page 1197/1356Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-41335(opens NVD record) | High | 8.8 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests. | Feb 16, 2023 |
| CVE-2022-41334(opens NVD record) | High | 8.8 | An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked. | Feb 16, 2023 |
| CVE-2022-40683(opens NVD record) | High | 7.8 | A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands | Feb 16, 2023 |
| CVE-2022-40678(opens NVD record) | High | 7.4 | An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords. | Feb 16, 2023 |
| CVE-2022-40677(opens NVD record) | High | 7.2 | A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters. | Feb 16, 2023 |
| CVE-2022-40675(opens NVD record) | Medium | 6.5 | Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decrypt and forge protocol communication messages. | Feb 16, 2023 |
| CVE-2022-39954(opens NVD record) | High | 7.3 | An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents. | Feb 16, 2023 |
| CVE-2022-39952(opens NVD record) | Critical | 9.8 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request. | Feb 16, 2023 |
| CVE-2022-39948(opens NVD record) | Medium | 4.8 | An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy) | Feb 16, 2023 |
| CVE-2022-38378(opens NVD record) | Medium | 4.2 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands. | Feb 16, 2023 |
| CVE-2022-38376(opens NVD record) | Medium | 6.1 | Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests. | Feb 16, 2023 |
| CVE-2022-38375(opens NVD record) | Critical | 9.1 | An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. | Feb 16, 2023 |
| CVE-2022-33871(opens NVD record) | Medium | 6.6 | A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `execute backup-local rename` and `execute backup-local show` operations. | Feb 16, 2023 |
| CVE-2022-33869(opens NVD record) | High | 8.8 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | Feb 16, 2023 |
| CVE-2022-30306(opens NVD record) | Medium | 6.6 | A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted password. | Feb 16, 2023 |
| CVE-2022-30304(opens NVD record) | Medium | 4.3 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer. | Feb 16, 2023 |
| CVE-2022-30303(opens NVD record) | High | 8.8 | An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests. | Feb 16, 2023 |
| CVE-2022-30300(opens NVD record) | Medium | 6.5 | A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. | Feb 16, 2023 |
| CVE-2022-30299(opens NVD record) | Medium | 5.3 | A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the underlying file system via specially crafted web requests. | Feb 16, 2023 |
| CVE-2022-29054(opens NVD record) | Low | 3.3 | A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it. | Feb 16, 2023 |
| CVE-2022-27489(opens NVD record) | High | 7.2 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | Feb 16, 2023 |
| CVE-2022-27482(opens NVD record) | High | 7.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.6, 6.0.x, 5.x.x allows attacker to execute arbitrary shell code as `root` via CLI commands. | Feb 16, 2023 |
| CVE-2022-26115(opens NVD record) | Medium | 5.9 | A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords. | Feb 16, 2023 |
| CVE-2021-43074(opens NVD record) | Medium | 4.3 | An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter. | Feb 16, 2023 |
| CVE-2021-42761(opens NVD record) | Critical | 9.0 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session. | Feb 16, 2023 |
| CVE-2021-42756(opens NVD record) | Critical | 9.8 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests. | Feb 16, 2023 |
| CVE-2023-24485(opens NVD record) | High | 7.8 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | Feb 16, 2023 |
| CVE-2023-24484(opens NVD record) | Medium | 5.5 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | Feb 16, 2023 |
| CVE-2023-24483(opens NVD record) | High | 7.8 | A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | Feb 16, 2023 |
| CVE-2023-23836(opens NVD record) | High | 7.2 | SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands. | Feb 15, 2023 |
| CVE-2023-23459(opens NVD record) | Critical | 9.1 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | Feb 15, 2023 |
| CVE-2022-47508(opens NVD record) | High | 7.5 | Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. | Feb 15, 2023 |
| CVE-2022-47507(opens NVD record) | High | 7.2 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | Feb 15, 2023 |
| CVE-2022-47506(opens NVD record) | High | 7.8 | SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands. | Feb 15, 2023 |
| CVE-2022-47504(opens NVD record) | High | 7.2 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | Feb 15, 2023 |
| CVE-2022-47503(opens NVD record) | High | 7.2 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | Feb 15, 2023 |
| CVE-2022-38111(opens NVD record) | High | 7.2 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | Feb 15, 2023 |
| CVE-2023-0361(opens NVD record) | High | 7.4 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection. | Feb 15, 2023 |
| CVE-2023-22368(opens NVD record) | High | 7.8 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Feb 15, 2023 |
| CVE-2023-23381(opens NVD record) | High | 7.8 | Visual Studio Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21823(opens NVD record) | High | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21815(opens NVD record) | High | 7.8 | Visual Studio Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21808(opens NVD record) | High | 7.8 | .NET and Visual Studio Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21778(opens NVD record) | High | 8.0 | Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21567(opens NVD record) | Medium | 5.6 | Visual Studio Denial of Service Vulnerability | Feb 14, 2023 |
| CVE-2023-21566(opens NVD record) | High | 7.8 | Visual Studio Elevation of Privilege Vulnerability | Feb 14, 2023 |
| CVE-2023-21553(opens NVD record) | High | 7.5 | Azure DevOps Server Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-23390(opens NVD record) | High | 7.8 | 3D Builder Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-23382(opens NVD record) | Medium | 6.5 | Azure Machine Learning Compute Instance Information Disclosure Vulnerability | Feb 14, 2023 |
| CVE-2023-23379(opens NVD record) | High | 7.8 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Feb 14, 2023 |