Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
33,036 matching · page 591/661Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-1053(opens NVD record) | Medium | 4.9 | Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav. | Feb 14, 2025 |
| CVE-2024-55904(opens NVD record) | High | 7.2 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. | Feb 14, 2025 |
| CVE-2024-10404(opens NVD record) | Medium | 5.5 | CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges could retrieve sensitive information including passwords; SNMP responses that contain AuthSecret and PrivSecret after collecting a “supportsave” or getting access to an already collected “supportsave”. NOTE: this issue exists because of an incomplete fix for CVE-2024-29952 | Feb 14, 2025 |
| CVE-2025-22480(opens NVD record) | High | 7.0 | Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. | Feb 13, 2025 |
| CVE-2025-21701(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen if a device is being unregistered while its number of channels are being modified. DEBUG_LOCKS_WARN_ON(lock->magic != lock) WARNING: CPU: 3 PID: 3754 at kernel/locking/mutex.c:564 __mutex_lock+0xc8a/0x1120 CPU: 3 UID: 0 PID: 3754 Comm: ethtool Not tainted 6.13.0-rc6+ #771 RIP: 0010:__mutex_lock+0xc8a/0x1120 Call Trace: <TASK> ethtool_check_max_channel+0x1ea/0x880 ethnl_set_channels+0x3c3/0xb10 ethnl_default_set_doit+0x306/0x650 genl_family_rcv_msg_doit+0x1e3/0x2c0 genl_rcv_msg+0x432/0x6f0 netlink_rcv_skb+0x13d/0x3b0 genl_rcv+0x28/0x40 netlink_unicast+0x42e/0x720 netlink_sendmsg+0x765/0xc20 __sys_sendto+0x3ac/0x420 __x64_sys_sendto+0xe0/0x1c0 do_syscall_64+0x95/0x180 entry_SYSCALL_64_after_hwframe+0x76/0x7e This is because unregister_netdevice_many_notify might run before the rtnl lock section of ethnl operations, eg. set_channels in the above example. In this example the rss lock would be destroyed by the device unregistration path before being used again, but in general running ethnl operations while dismantle has started is not a good idea. Fix this by denying any operation on devices being unregistered. A check was already there in ethnl_ops_begin, but not wide enough. Note that the same issue cannot be seen on the ioctl version (__dev_ethtool) because the device reference is retrieved from within the rtnl lock section there. Once dismantle started, the net device is unlisted and no reference will be found. | Feb 13, 2025 |
| CVE-2025-1247(opens NVD record) | High | 8.3 | A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information. | Feb 13, 2025 |
| CVE-2025-0111(opens NVD record) | Medium | 6.5 | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software. | Feb 12, 2025 |
| CVE-2025-0108(opens NVD record) | Critical | 9.1 | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software. | Feb 12, 2025 |
| CVE-2025-1215(opens NVD record) | Low | 2.8 | A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component. | Feb 12, 2025 |
| CVE-2024-6097(opens NVD record) | Medium | 5.3 | In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability. | Feb 12, 2025 |
| CVE-2024-11629(opens NVD record) | High | 7.1 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. | Feb 12, 2025 |
| CVE-2024-11628(opens NVD record) | Medium | 4.1 | In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | Feb 12, 2025 |
| CVE-2025-0556(opens NVD record) | High | 8.8 | In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing. | Feb 12, 2025 |
| CVE-2025-0332(opens NVD record) | High | 7.8 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | Feb 12, 2025 |
| CVE-2024-12629(opens NVD record) | Medium | 4.1 | In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | Feb 12, 2025 |
| CVE-2024-11343(opens NVD record) | High | 8.3 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | Feb 12, 2025 |
| CVE-2025-1244(opens NVD record) | High | 8.8 | A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect. | Feb 12, 2025 |
| CVE-2024-12251(opens NVD record) | High | 7.8 | In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements. | Feb 12, 2025 |
| CVE-2025-21699(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag Truncate an inode's address space when flipping the GFS2_DIF_JDATA flag: depending on that flag, the pages in the address space will either use buffer heads or iomap_folio_state structs, and we cannot mix the two. | Feb 12, 2025 |
| CVE-2025-21697(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after job completion After a job completes, the corresponding pointer in the device must be set to NULL. Failing to do so triggers a warning when unloading the driver, as it appears the job is still active. To prevent this, assign the job pointer to NULL after completing the job, indicating the job has finished. | Feb 12, 2025 |
| CVE-2024-57952(opens NVD record) | High | 7.1 | In the Linux kernel, the following vulnerability has been resolved: Revert "libfs: fix infinite directory reads for offset dir" The current directory offset allocator (based on mtree_alloc_cyclic) stores the next offset value to return in octx->next_offset. This mechanism typically returns values that increase monotonically over time. Eventually, though, the newly allocated offset value wraps back to a low number (say, 2) which is smaller than other already- allocated offset values. Yu Kuai <yukuai3@huawei.com> reports that, after commit 64a7ce76fb90 ("libfs: fix infinite directory reads for offset dir"), if a directory's offset allocator wraps, existing entries are no longer visible via readdir/getdents because offset_readdir() stops listing entries once an entry's offset is larger than octx->next_offset. These entries vanish persistently -- they can be looked up, but will never again appear in readdir(3) output. The reason for this is that the commit treats directory offsets as monotonically increasing integer values rather than opaque cookies, and introduces this comparison: if (dentry2offset(dentry) >= last_index) { On 64-bit platforms, the directory offset value upper bound is 2^63 - 1. Directory offsets will monotonically increase for millions of years without wrapping. On 32-bit platforms, however, LONG_MAX is 2^31 - 1. The allocator can wrap after only a few weeks (at worst). Revert commit 64a7ce76fb90 ("libfs: fix infinite directory reads for offset dir") to prepare for a fix that can work properly on 32-bit systems and might apply to recent LTS kernels where shmem employs the simple_offset mechanism. | Feb 12, 2025 |
| CVE-2024-29172(opens NVD record) | Medium | 5.9 | Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service. | Feb 12, 2025 |
| CVE-2024-29171(opens NVD record) | Medium | 5.9 | Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure. | Feb 12, 2025 |
| CVE-2025-23359(opens NVD record) | High | 8.3 | NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | Feb 12, 2025 |
| CVE-2024-53880(opens NVD record) | Medium | 4.9 | NVIDIA Triton Inference Server contains a vulnerability in the model loading API, where a user could cause an integer overflow or wraparound error by loading a model with an extra-large file size that overflows an internal variable. A successful exploit of this vulnerability might lead to denial of service. | Feb 12, 2025 |
| CVE-2020-3432(opens NVD record) | Medium | 5.6 | A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file. If the file is a critical systems file, the exploit could lead to a denial of service condition. To exploit this vulnerability, the attacker would need to have valid credentials on the system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. | Feb 12, 2025 |
| CVE-2022-37660(opens NVD record) | Medium | 6.5 | In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association. | Feb 11, 2025 |
| CVE-2024-12833(opens NVD record) | Medium | 6.1 | Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371. | Feb 11, 2025 |
| CVE-2025-24042(opens NVD record) | High | 7.3 | Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-24039(opens NVD record) | High | 7.3 | Visual Studio Code Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-24036(opens NVD record) | High | 7.0 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-21420(opens NVD record) | High | 7.8 | Windows Disk Cleanup Tool Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-21419(opens NVD record) | High | 7.1 | Windows Setup Files Cleanup Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-21418(opens NVD record) | High | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-21414(opens NVD record) | High | 7.0 | Windows Core Messaging Elevation of Privileges Vulnerability | Feb 11, 2025 |
| CVE-2025-21410(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21407(opens NVD record) | High | 8.8 | Windows Telephony Service Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21406(opens NVD record) | High | 8.8 | Windows Telephony Service Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21400(opens NVD record) | High | 8.0 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21397(opens NVD record) | High | 7.8 | Microsoft Office Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21394(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21392(opens NVD record) | High | 7.8 | Microsoft Office Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21391(opens NVD record) | High | 7.1 | Windows Storage Elevation of Privilege Vulnerability | Feb 11, 2025 |
| CVE-2025-21390(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21387(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21386(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21383(opens NVD record) | High | 7.8 | Microsoft Excel Information Disclosure Vulnerability | Feb 11, 2025 |
| CVE-2025-21381(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21379(opens NVD record) | High | 7.1 | DHCP Client Service Remote Code Execution Vulnerability | Feb 11, 2025 |
| CVE-2025-21377(opens NVD record) | Medium | 6.5 | NTLM Hash Disclosure Spoofing Vulnerability | Feb 11, 2025 |