Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
67,705 matching · page 1199/1355Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-21692(opens NVD record) | Critical | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21691(opens NVD record) | High | 7.5 | Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability | Feb 14, 2023 |
| CVE-2023-21690(opens NVD record) | Critical | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21689(opens NVD record) | Critical | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21688(opens NVD record) | High | 7.8 | NT OS Kernel Elevation of Privilege Vulnerability | Feb 14, 2023 |
| CVE-2023-21687(opens NVD record) | Medium | 5.5 | HTTP.sys Information Disclosure Vulnerability | Feb 14, 2023 |
| CVE-2023-21686(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21685(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21684(opens NVD record) | High | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21573(opens NVD record) | Medium | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 14, 2023 |
| CVE-2023-21572(opens NVD record) | Medium | 6.5 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 14, 2023 |
| CVE-2023-21571(opens NVD record) | Medium | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 14, 2023 |
| CVE-2023-21570(opens NVD record) | Medium | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 14, 2023 |
| CVE-2023-21568(opens NVD record) | High | 7.3 | Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21564(opens NVD record) | High | 7.1 | Azure DevOps Server Cross-Site Scripting Vulnerability | Feb 14, 2023 |
| CVE-2023-21529(opens NVD record) | High | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-21528(opens NVD record) | High | 7.8 | Microsoft SQL Server Remote Code Execution Vulnerability | Feb 14, 2023 |
| CVE-2023-25725(opens NVD record) | Critical | 9.1 | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31. | Feb 14, 2023 |
| CVE-2022-22564(opens NVD record) | Medium | 5.9 | Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. | Feb 14, 2023 |
| CVE-2023-0655(opens NVD record) | Medium | 5.3 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. | Feb 14, 2023 |
| CVE-2023-24187(opens NVD record) | High | 7.8 | An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile. | Feb 14, 2023 |
| CVE-2023-25717(opens NVD record) | Critical | 9.8 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. | Feb 13, 2023 |
| CVE-2023-24188(opens NVD record) | Critical | 9.1 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | Feb 13, 2023 |
| CVE-2023-0169(opens NVD record) | Medium | 5.4 | The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | Feb 13, 2023 |
| CVE-2022-45725(opens NVD record) | High | 8.8 | Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request | Feb 13, 2023 |
| CVE-2022-45724(opens NVD record) | Medium | 5.4 | Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests. | Feb 13, 2023 |
| CVE-2022-45455(opens NVD record) | High | 7.8 | Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984. | Feb 13, 2023 |
| CVE-2022-45454(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984. | Feb 13, 2023 |
| CVE-2022-34397(opens NVD record) | Medium | 6.9 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized. | Feb 13, 2023 |
| CVE-2023-24572(opens NVD record) | Medium | 4.7 | Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | Feb 13, 2023 |
| CVE-2023-23697(opens NVD record) | Medium | 4.7 | Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | Feb 13, 2023 |
| CVE-2023-20076(opens NVD record) | High | 7.2 | A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system. | Feb 12, 2023 |
| CVE-2022-43869(opens NVD record) | Medium | 6.5 | IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539. | Feb 12, 2023 |
| CVE-2022-43779(opens NVD record) | High | 7.0 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability. | Feb 12, 2023 |
| CVE-2022-42444(opens NVD record) | Medium | 4.9 | IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow. A remote privileged user could overflow a buffer and cause the application to crash. IBM X-Force ID: 238538. | Feb 12, 2023 |
| CVE-2022-42436(opens NVD record) | Medium | 4.0 | IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files. IBM X-Force ID: 238206. | Feb 12, 2023 |
| CVE-2022-42292(opens NVD record) | Medium | 5.0 | NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of privilege or limited data tampering. | Feb 12, 2023 |
| CVE-2022-41731(opens NVD record) | High | 8.6 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. | Feb 12, 2023 |
| CVE-2022-38396(opens NVD record) | High | 7.8 | HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This potential vulnerability was remediated starting with Windows 10 versions 21H2 on October 31, 2021. | Feb 12, 2023 |
| CVE-2022-46755(opens NVD record) | Medium | 4.9 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized. | Feb 11, 2023 |
| CVE-2022-46754(opens NVD record) | High | 8.7 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. | Feb 11, 2023 |
| CVE-2022-46678(opens NVD record) | Medium | 4.9 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized. | Feb 11, 2023 |
| CVE-2022-46677(opens NVD record) | Medium | 6.8 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized. | Feb 11, 2023 |
| CVE-2022-46676(opens NVD record) | Medium | 4.9 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized. | Feb 11, 2023 |
| CVE-2022-46675(opens NVD record) | Medium | 5.3 | Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research. | Feb 11, 2023 |
| CVE-2022-45104(opens NVD record) | High | 8.8 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system. | Feb 11, 2023 |
| CVE-2022-34451(opens NVD record) | Medium | 4.8 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server. | Feb 11, 2023 |
| CVE-2022-34450(opens NVD record) | Medium | 6.7 | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root. | Feb 11, 2023 |
| CVE-2022-34449(opens NVD record) | Medium | 6.0 | PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. | Feb 11, 2023 |
| CVE-2022-34448(opens NVD record) | High | 8.8 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions. | Feb 11, 2023 |