Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
34,808 matching · page 649/697Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-48889(opens NVD record) | High | 7.2 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests. | Dec 18, 2024 |
| CVE-2023-34990(opens NVD record) | Critical | 9.8 | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests. | Dec 18, 2024 |
| CVE-2024-47104(opens NVD record) | Medium | 6.8 | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges. | Dec 18, 2024 |
| CVE-2024-47480(opens NVD record) | High | 7.8 | Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file system access. | Dec 18, 2024 |
| CVE-2024-10973(opens NVD record) | Medium | 5.7 | A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information. | Dec 17, 2024 |
| CVE-2024-49820(opens NVD record) | Low | 3.7 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | Dec 17, 2024 |
| CVE-2024-49819(opens NVD record) | Medium | 4.1 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors. | Dec 17, 2024 |
| CVE-2024-49818(opens NVD record) | Medium | 4.3 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | Dec 17, 2024 |
| CVE-2024-49817(opens NVD record) | Medium | 4.4 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user. | Dec 17, 2024 |
| CVE-2024-49816(opens NVD record) | Medium | 4.9 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user. | Dec 17, 2024 |
| CVE-2024-53144(opens NVD record) | High | 8.8 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805 | Dec 17, 2024 |
| CVE-2024-54677(opens NVD record) | Medium | 5.3 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue. | Dec 17, 2024 |
| CVE-2024-50379(opens NVD record) | Critical | 9.8 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue. | Dec 17, 2024 |
| CVE-2024-52542(opens NVD record) | Medium | 4.4 | Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information tampering. | Dec 17, 2024 |
| CVE-2024-12356(opens NVD record) | Critical | 9.8 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | Dec 17, 2024 |
| CVE-2024-37776(opens NVD record) | Medium | 4.8 | A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens. | Dec 16, 2024 |
| CVE-2024-37775(opens NVD record) | High | 7.5 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check. | Dec 16, 2024 |
| CVE-2024-37774(opens NVD record) | High | 8.0 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | Dec 16, 2024 |
| CVE-2024-37773(opens NVD record) | Medium | 4.8 | An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen. | Dec 16, 2024 |
| CVE-2024-31892(opens NVD record) | High | 7.5 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements. | Dec 14, 2024 |
| CVE-2024-31891(opens NVD record) | High | 7.8 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system. | Dec 14, 2024 |
| CVE-2024-55956(opens NVD record) | Critical | 9.8 | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | Dec 13, 2024 |
| CVE-2024-47984(opens NVD record) | Medium | 4.4 | Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back to stable state. | Dec 13, 2024 |
| CVE-2024-28980(opens NVD record) | Medium | 6.5 | Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | Dec 13, 2024 |
| CVE-2024-24902(opens NVD record) | Medium | 6.6 | Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time. | Dec 13, 2024 |
| CVE-2024-48008(opens NVD record) | Medium | 5.3 | Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information | Dec 13, 2024 |
| CVE-2024-48007(opens NVD record) | Medium | 5.3 | Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data. | Dec 13, 2024 |
| CVE-2024-38488(opens NVD record) | Medium | 6.5 | Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner. | Dec 13, 2024 |
| CVE-2024-22461(opens NVD record) | High | 8.8 | Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system. | Dec 13, 2024 |
| CVE-2024-49147(opens NVD record) | Critical | 9.3 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. | Dec 12, 2024 |
| CVE-2024-49071(opens NVD record) | Medium | 6.5 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | Dec 12, 2024 |
| CVE-2024-47238(opens NVD record) | High | 7.5 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | Dec 12, 2024 |
| CVE-2024-52901(opens NVD record) | Medium | 6.5 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation. | Dec 12, 2024 |
| CVE-2024-54122(opens NVD record) | Medium | 6.2 | Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability. | Dec 12, 2024 |
| CVE-2024-54119(opens NVD record) | Medium | 6.2 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |
| CVE-2024-54117(opens NVD record) | Medium | 6.2 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |
| CVE-2024-54116(opens NVD record) | Medium | 4.3 | Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | Dec 12, 2024 |
| CVE-2024-54115(opens NVD record) | Medium | 4.3 | Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54114(opens NVD record) | Medium | 4.4 | Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54113(opens NVD record) | Medium | 6.5 | Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption. | Dec 12, 2024 |
| CVE-2024-54112(opens NVD record) | Medium | 5.5 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |
| CVE-2024-54111(opens NVD record) | Medium | 5.7 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54110(opens NVD record) | Medium | 6.2 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |
| CVE-2024-54109(opens NVD record) | Medium | 6.5 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54108(opens NVD record) | Medium | 6.5 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54107(opens NVD record) | High | 7.1 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54106(opens NVD record) | High | 7.1 | Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54105(opens NVD record) | Medium | 5.1 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | Dec 12, 2024 |
| CVE-2024-54104(opens NVD record) | Medium | 6.2 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |
| CVE-2024-54103(opens NVD record) | Medium | 6.1 | Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Dec 12, 2024 |