Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
32,900 matching · page 564/658Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-30391(opens NVD record) | High | 8.1 | Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | Apr 30, 2025 |
| CVE-2025-30390(opens NVD record) | Critical | 9.9 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | Apr 30, 2025 |
| CVE-2025-30389(opens NVD record) | High | 8.7 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | Apr 30, 2025 |
| CVE-2025-21416(opens NVD record) | High | 8.5 | Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | Apr 30, 2025 |
| CVE-2025-3599(opens NVD record) | Medium | 6.5 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user. | Apr 30, 2025 |
| CVE-2025-3910(opens NVD record) | Medium | 5.4 | A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication. | Apr 29, 2025 |
| CVE-2025-1551(opens NVD record) | Medium | 6.1 | IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Apr 29, 2025 |
| CVE-2025-3891(opens NVD record) | High | 7.5 | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability. | Apr 29, 2025 |
| CVE-2024-58099(opens NVD record) | High | 8.6 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3. If a BPF program for native XDP adds an encapsulation header such as IPIP and transmits the packet out the same interface, then in case of vmxnet3 a corrupted packet is being sent and subsequently dropped on the path. vmxnet3_xdp_xmit_frame() which is called e.g. via vmxnet3_run_xdp() through vmxnet3_xdp_xmit_back() calculates an incorrect DMA address: page = virt_to_page(xdpf->data); tbi->dma_addr = page_pool_get_dma_addr(page) + VMXNET3_XDP_HEADROOM; dma_sync_single_for_device(&adapter->pdev->dev, tbi->dma_addr, buf_size, DMA_TO_DEVICE); The above assumes a fixed offset (VMXNET3_XDP_HEADROOM), but the XDP BPF program could have moved xdp->data. While the passed buf_size is correct (xdpf->len), the dma_addr needs to have a dynamic offset which can be calculated as xdpf->data - (void *)xdpf, that is, xdp->data - xdp->data_hard_start. | Apr 29, 2025 |
| CVE-2025-45953(opens NVD record) | Critical | 9.1 | A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely | Apr 28, 2025 |
| CVE-2025-45949(opens NVD record) | Critical | 9.8 | A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover. | Apr 28, 2025 |
| CVE-2025-45947(opens NVD record) | Critical | 9.8 | An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component | Apr 28, 2025 |
| CVE-2025-23377(opens NVD record) | Medium | 4.2 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs. | Apr 28, 2025 |
| CVE-2025-23376(opens NVD record) | Low | 2.3 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | Apr 28, 2025 |
| CVE-2025-23375(opens NVD record) | High | 7.8 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | Apr 28, 2025 |
| CVE-2024-52888(opens NVD record) | Medium | 5.4 | For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties. | Apr 27, 2025 |
| CVE-2024-52887(opens NVD record) | Low | 3.5 | Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list. | Apr 27, 2025 |
| CVE-2025-32986(opens NVD record) | High | 7.5 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint. | Apr 25, 2025 |
| CVE-2025-32985(opens NVD record) | Critical | 9.8 | NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. | Apr 25, 2025 |
| CVE-2025-32984(opens NVD record) | Medium | 6.1 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter. | Apr 25, 2025 |
| CVE-2025-32983(opens NVD record) | High | 7.5 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace. | Apr 25, 2025 |
| CVE-2025-32982(opens NVD record) | High | 7.5 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module. | Apr 25, 2025 |
| CVE-2025-32981(opens NVD record) | High | 7.1 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File. | Apr 25, 2025 |
| CVE-2025-32979(opens NVD record) | Medium | 6.5 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users. | Apr 25, 2025 |
| CVE-2025-3928(opens NVD record) | High | 8.8 | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28. | Apr 25, 2025 |
| CVE-2025-2986(opens NVD record) | Medium | 5.5 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Apr 25, 2025 |
| CVE-2025-31324(opens NVD record) | Critical | 10.0 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | Apr 24, 2025 |
| CVE-2025-27820(opens NVD record) | High | 7.5 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | Apr 24, 2025 |
| CVE-2025-1976(opens NVD record) | Medium | 6.7 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. | Apr 24, 2025 |
| CVE-2025-25046(opens NVD record) | Low | 3.7 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. | Apr 23, 2025 |
| CVE-2025-25045(opens NVD record) | Medium | 4.3 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. | Apr 23, 2025 |
| CVE-2024-22351(opens NVD record) | Medium | 6.3 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | Apr 23, 2025 |
| CVE-2025-46400(opens NVD record) | Medium | 5.5 | In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. | Apr 23, 2025 |
| CVE-2025-46399(opens NVD record) | Medium | 5.5 | A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. | Apr 23, 2025 |
| CVE-2025-46398(opens NVD record) | Medium | 5.5 | In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. | Apr 23, 2025 |
| CVE-2025-46397(opens NVD record) | High | 7.8 | A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. | Apr 23, 2025 |
| CVE-2025-2767(opens NVD record) | Critical | 9.6 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the User-Agent HTTP header. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24407. | Apr 23, 2025 |
| CVE-2025-34028(opens NVD record) | Critical | 10.0 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438. | Apr 22, 2025 |
| CVE-2025-27907(opens NVD record) | Medium | 4.1 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | Apr 22, 2025 |
| CVE-2025-23251(opens NVD record) | High | 7.6 | NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | Apr 22, 2025 |
| CVE-2025-23250(opens NVD record) | High | 7.6 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering. | Apr 22, 2025 |
| CVE-2025-23249(opens NVD record) | High | 7.6 | NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | Apr 22, 2025 |
| CVE-2025-1951(opens NVD record) | High | 8.4 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges. | Apr 22, 2025 |
| CVE-2025-1950(opens NVD record) | Critical | 9.3 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source. | Apr 22, 2025 |
| CVE-2025-2987(opens NVD record) | Low | 3.8 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | Apr 22, 2025 |
| CVE-2025-29287(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | Apr 21, 2025 |
| CVE-2024-41446(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function. | Apr 21, 2025 |
| CVE-2025-29513(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator. | Apr 18, 2025 |
| CVE-2025-29512(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database. | Apr 18, 2025 |
| CVE-2025-1697(opens NVD record) | High | 7.8 | A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing software updates to mitigate this potential vulnerability. | Apr 18, 2025 |