Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
62,958 matching · page 921/1260Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-38144(opens NVD record) | High | 8.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38143(opens NVD record) | Medium | 4.2 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38142(opens NVD record) | High | 7.8 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38141(opens NVD record) | High | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38140(opens NVD record) | Critical | 9.8 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38138(opens NVD record) | High | 7.5 | Windows Deployment Services Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38137(opens NVD record) | High | 7.0 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38136(opens NVD record) | High | 7.0 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38135(opens NVD record) | High | 7.8 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38134(opens NVD record) | High | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38133(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38132(opens NVD record) | High | 7.5 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Aug 13, 2024 |
| CVE-2024-38131(opens NVD record) | High | 8.8 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38130(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38128(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38127(opens NVD record) | High | 7.8 | Windows Hyper-V Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38126(opens NVD record) | High | 7.5 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Aug 13, 2024 |
| CVE-2024-38125(opens NVD record) | High | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38123(opens NVD record) | Medium | 4.4 | Windows Bluetooth Driver Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38122(opens NVD record) | Medium | 5.5 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38121(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38120(opens NVD record) | High | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38118(opens NVD record) | Medium | 5.5 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Aug 13, 2024 |
| CVE-2024-38117(opens NVD record) | High | 7.8 | NTFS Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38116(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38115(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38114(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-38109(opens NVD record) | Critical | 9.1 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | Aug 13, 2024 |
| CVE-2024-38108(opens NVD record) | Critical | 9.3 | Azure Stack Hub Spoofing Vulnerability | Aug 13, 2024 |
| CVE-2024-38107(opens NVD record) | High | 7.8 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38106(opens NVD record) | High | 7.0 | Windows Kernel Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38098(opens NVD record) | High | 7.8 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38084(opens NVD record) | High | 7.8 | Microsoft OfficePlus Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-38063(opens NVD record) | Critical | 9.8 | Windows TCP/IP Remote Code Execution Vulnerability | Aug 13, 2024 |
| CVE-2024-37968(opens NVD record) | High | 7.5 | Windows DNS Spoofing Vulnerability | Aug 13, 2024 |
| CVE-2024-29995(opens NVD record) | High | 8.1 | Windows Kerberos Elevation of Privilege Vulnerability | Aug 13, 2024 |
| CVE-2024-36505(opens NVD record) | Medium | 5.1 | An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system. | Aug 13, 2024 |
| CVE-2024-21757(opens NVD record) | Medium | 6.1 | A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup. | Aug 13, 2024 |
| CVE-2023-26211(opens NVD record) | Medium | 6.8 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | Aug 13, 2024 |
| CVE-2022-45862(opens NVD record) | Low | 3.7 | An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. | Aug 13, 2024 |
| CVE-2022-27486(opens NVD record) | Medium | 6.6 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 through 6.3.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 allows an authenticated attacker to execute shell code as `root` via `execute` CLI commands. | Aug 13, 2024 |
| CVE-2024-41623(opens NVD record) | Critical | 9.8 | An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload | Aug 13, 2024 |
| CVE-2024-35124(opens NVD record) | High | 7.5 | A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674. | Aug 13, 2024 |
| CVE-2024-41774(opens NVD record) | Medium | 4.8 | IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348. | Aug 13, 2024 |
| CVE-2024-40697(opens NVD record) | High | 7.5 | IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895. | Aug 13, 2024 |
| CVE-2022-38382(opens NVD record) | Medium | 4.7 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672. | Aug 13, 2024 |
| CVE-2024-7700(opens NVD record) | Medium | 6.5 | A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration, potentially allowing unauthorized command execution during host registration. Although this issue requires user interaction to execute injected commands, it poses a significant risk if an unsuspecting user runs the generated registration script. | Aug 12, 2024 |
| CVE-2024-42474(opens NVD record) | Medium | 6.5 | Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is enabled. An attacker could utilize the vulnerability to leak the password hash of the Windows user running Streamlit. The vulnerability was patched on Jul 25, 2024, as part of Streamlit open source version 1.37.0. The vulnerability only affects Windows. | Aug 12, 2024 |
| CVE-2023-7249(opens NVD record) | Critical | 9.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | Aug 12, 2024 |
| CVE-2024-42258(opens NVD record) | High | 7.1 | In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines Yves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don't force huge page alignment on 32 bit") didn't work for x86_32 [1]. It is because x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT. !CONFIG_64BIT should cover all 32 bit machines. [1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/ | Aug 12, 2024 |