Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
62,388 matching · page 910/1248Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-38126(opens NVD record) | High | 7.5 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Aug 13, 2024 |
| CVE-2024-38125(opens NVD record) | High | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38123(opens NVD record) | Medium | 4.4 | Windows Bluetooth Driver Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38122(opens NVD record) | Medium | 5.5 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38121(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38120(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38118(opens NVD record) | Medium | 5.5 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38117(opens NVD record) | High | 7.8 | NTFS Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38116(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38115(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38114(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38109(opens NVD record) | Critical | 9.1 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | Aug 13, 2024 |
| CVE-2024-38108(opens NVD record) | Critical | 9.3 | Azure Stack Hub Spoofing Vulnerability | Aug 13, 2024 |
| CVE-2024-38107(opens NVD record) | High | 7.8 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38106(opens NVD record) | High | 7.0 | Windows Kernel Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38098(opens NVD record) | High | 7.8 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38084(opens NVD record) | High | 7.8 | Microsoft OfficePlus Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38063(opens NVD record) | Critical | 9.8 | Windows TCP/IP Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-37968(opens NVD record) | High | 7.5 | Windows DNS Spoofing Vulnerability | Aug 13, 2024 |
| CVE-2024-29995(opens NVD record) | High | 8.1 | Windows Kerberos Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-36505(opens NVD record) | Medium | 5.1 | An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system. | Aug 13, 2024 |
| CVE-2024-21757(opens NVD record) | Medium | 6.1 | A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup. | Aug 13, 2024 |
| CVE-2023-26211(opens NVD record) | Medium | 6.8 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | Aug 13, 2024 |
| CVE-2022-45862(opens NVD record) | Low | 3.7 | An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. | Aug 13, 2024 |
| CVE-2022-27486(opens NVD record) | Medium | 6.6 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 through 6.3.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 allows an authenticated attacker to execute shell code as `root` via `execute` CLI commands. | Aug 13, 2024 |
| CVE-2024-41623(opens NVD record) | Critical | 9.8 | An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload | Aug 13, 2024 |
| CVE-2024-35124(opens NVD record) | High | 7.5 | A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674. | Aug 13, 2024 |
| CVE-2024-41774(opens NVD record) | Medium | 4.8 | IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348. | Aug 13, 2024 |
| CVE-2024-40697(opens NVD record) | High | 7.5 | IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895. | Aug 13, 2024 |
| CVE-2022-38382(opens NVD record) | Medium | 4.7 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672. | Aug 13, 2024 |
| CVE-2024-7700(opens NVD record) | Medium | 6.5 | A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration, potentially allowing unauthorized command execution during host registration. Although this issue requires user interaction to execute injected commands, it poses a significant risk if an unsuspecting user runs the generated registration script. | Aug 12, 2024 |
| CVE-2024-42474(opens NVD record) | Medium | 6.5 | Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is enabled. An attacker could utilize the vulnerability to leak the password hash of the Windows user running Streamlit. The vulnerability was patched on Jul 25, 2024, as part of Streamlit open source version 1.37.0. The vulnerability only affects Windows. | Aug 12, 2024 |
| CVE-2023-7249(opens NVD record) | Critical | 9.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | Aug 12, 2024 |
| CVE-2024-42258(opens NVD record) | High | 7.1 | In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines Yves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don't force huge page alignment on 32 bit") didn't work for x86_32 [1]. It is because x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT. !CONFIG_64BIT should cover all 32 bit machines. [1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/ | Aug 12, 2024 |
| CVE-2024-7557(opens NVD record) | High | 8.8 | A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. However, credentials from one model can be used to access other models and APIs within the same namespace. The exposed ServiceAccount tokens, visible in the UI, can be utilized with oc --token={token} to exploit the elevated view privileges associated with the ServiceAccount, leading to unauthorized access to additional resources. | Aug 12, 2024 |
| CVE-2024-7006(opens NVD record) | High | 7.5 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service. | Aug 12, 2024 |
| CVE-2024-5527(opens NVD record) | High | 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration. | Aug 12, 2024 |
| CVE-2024-5487(opens NVD record) | High | 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. | Aug 12, 2024 |
| CVE-2024-42467(opens NVD record) | Critical | 10.0 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF) to induce GET HTTP requests to internal-only servers, in case openHAB is exposed in a non-private network. Furthermore, this proxy-feature can also be exploited as a Cross-Site Scripting (XSS) vulnerability, as an attacker is able to re-route a request to their server and return a page with malicious JavaScript code. Since the browser receives this data directly from the openHAB CometVisu UI, this JavaScript code will be executed with the origin of the CometVisu UI. This allows an attacker to exploit call endpoints on an openHAB server even if the openHAB server is located in a private network. (e.g. by sending an openHAB admin a link that proxies malicious JavaScript.) This issue may lead up to Remote Code Execution (RCE) when chained with other vulnerabilities. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch. | Aug 12, 2024 |
| CVE-2024-38219(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Aug 12, 2024 |
| CVE-2024-38218(opens NVD record) | High | 8.4 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | Aug 12, 2024 |
| CVE-2024-38200(opens NVD record) | Medium | 6.5 | Microsoft Office Spoofing Vulnerability | Aug 12, 2024 |
| CVE-2024-36518(opens NVD record) | High | 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard. | Aug 12, 2024 |
| CVE-2024-36462(opens NVD record) | High | 7.5 | Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance of the affected system. | Aug 12, 2024 |
| CVE-2024-36461(opens NVD record) | Critical | 9.1 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | Aug 12, 2024 |
| CVE-2024-36460(opens NVD record) | High | 8.1 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | Aug 12, 2024 |
| CVE-2024-36035(opens NVD record) | High | 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. | Aug 12, 2024 |
| CVE-2024-36034(opens NVD record) | High | 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. | Aug 12, 2024 |
| CVE-2024-22123(opens NVD record) | Low | 2.7 | Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI. | Aug 12, 2024 |
| CVE-2024-22122(opens NVD record) | Low | 3.0 | Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem. | Aug 12, 2024 |