Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
62,958 matching · page 926/1260Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-41017(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: jfs: don't walk off the end of ealist Add a check before visiting the members of ea to make sure each ea stays within the ealist. | Jul 29, 2024 |
| CVE-2024-41016(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved with additional space requested. It's better to check if the memory is out of bound before memcmp, although this possibility mainly comes from crafted poisonous images. | Jul 29, 2024 |
| CVE-2024-41015(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_check_dir_entry() This adds sanity checks for ocfs2_dir_entry to make sure all members of ocfs2_dir_entry don't stray beyond valid memory region. | Jul 29, 2024 |
| CVE-2024-41014(opens NVD record) | High | 7.1 | In the Linux kernel, the following vulnerability has been resolved: xfs: add bounds checking to xlog_recover_process_data There is a lack of verification of the space occupied by fixed members of xlog_op_header in the xlog_recover_process_data. We can create a crafted image to trigger an out of bounds read by following these steps: 1) Mount an image of xfs, and do some file operations to leave records 2) Before umounting, copy the image for subsequent steps to simulate abnormal exit. Because umount will ensure that tail_blk and head_blk are the same, which will result in the inability to enter xlog_recover_process_data 3) Write a tool to parse and modify the copied image in step 2 4) Make the end of the xlog_op_header entries only 1 byte away from xlog_rec_header->h_size 5) xlog_rec_header->h_num_logops++ 6) Modify xlog_rec_header->h_crc Fix: Add a check to make sure there is sufficient space to access fixed members of xlog_op_header. | Jul 29, 2024 |
| CVE-2024-37381(opens NVD record) | High | 8.0 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code. | Jul 29, 2024 |
| CVE-2024-41628(opens NVD record) | High | 7.5 | Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API. | Jul 26, 2024 |
| CVE-2024-38872(opens NVD record) | High | 8.3 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. | Jul 26, 2024 |
| CVE-2024-38871(opens NVD record) | High | 8.3 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. | Jul 26, 2024 |
| CVE-2024-40689(opens NVD record) | Medium | 6.0 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719. | Jul 26, 2024 |
| CVE-2024-38103(opens NVD record) | Medium | 5.9 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Jul 25, 2024 |
| CVE-2024-28772(opens NVD record) | Medium | 6.8 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645. | Jul 25, 2024 |
| CVE-2022-32759(opens NVD record) | Medium | 5.3 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | Jul 25, 2024 |
| CVE-2024-39674(opens NVD record) | Medium | 6.2 | Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability. | Jul 25, 2024 |
| CVE-2024-39673(opens NVD record) | Medium | 6.8 | Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 25, 2024 |
| CVE-2024-39672(opens NVD record) | High | 8.4 | Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability. | Jul 25, 2024 |
| CVE-2024-39671(opens NVD record) | Critical | 9.3 | Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 25, 2024 |
| CVE-2024-39670(opens NVD record) | Medium | 6.2 | Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability. | Jul 25, 2024 |
| CVE-2023-7271(opens NVD record) | Medium | 5.5 | Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability. | Jul 25, 2024 |
| CVE-2024-37084(opens NVD record) | Critical | 9.8 | In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server | Jul 25, 2024 |
| CVE-2024-6972(opens NVD record) | Medium | 6.5 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. | Jul 25, 2024 |
| CVE-2024-4811(opens NVD record) | Low | 2.2 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | Jul 25, 2024 |
| CVE-2024-41136(opens NVD record) | Medium | 6.8 | An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Jul 24, 2024 |
| CVE-2024-40495(opens NVD record) | High | 8.0 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function. | Jul 24, 2024 |
| CVE-2024-37533(opens NVD record) | Low | 2.4 | IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727. | Jul 24, 2024 |
| CVE-2024-7079(opens NVD record) | Medium | 6.5 | A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does not verify the validity of the user's credentials. As a result, unauthenticated users can access this endpoint. | Jul 24, 2024 |
| CVE-2024-40575(opens NVD record) | Medium | 5.5 | An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes | Jul 24, 2024 |
| CVE-2024-22444(opens NVD record) | Medium | 6.1 | A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface. | Jul 24, 2024 |
| CVE-2024-41914(opens NVD record) | High | 8.1 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | Jul 24, 2024 |
| CVE-2024-22443(opens NVD record) | High | 7.2 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. | Jul 24, 2024 |
| CVE-2024-6327(opens NVD record) | Critical | 9.9 | In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability. | Jul 24, 2024 |
| CVE-2024-6096(opens NVD record) | High | 8.8 | In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability. | Jul 24, 2024 |
| CVE-2023-32471(opens NVD record) | Medium | 6.0 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits. | Jul 24, 2024 |
| CVE-2023-32466(opens NVD record) | Medium | 5.7 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | Jul 24, 2024 |
| CVE-2024-38176(opens NVD record) | High | 8.1 | An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | Jul 23, 2024 |
| CVE-2024-38164(opens NVD record) | Critical | 9.6 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | Jul 23, 2024 |
| CVE-2024-41836(opens NVD record) | Medium | 5.5 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jul 23, 2024 |
| CVE-2024-41012(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a range in the middle). After the bug has been triggered, use-after-free reads will occur in lock_get_status() when userspace reads /proc/locks. This can likely be used to read arbitrary kernel memory, but can't corrupt kernel memory. Fix it by calling locks_remove_posix() instead, which is designed to reliably get rid of POSIX locks associated with the given file and files_struct and is also used by filp_flush(). | Jul 23, 2024 |
| CVE-2024-6913(opens NVD record) | High | 8.8 | Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0. | Jul 22, 2024 |
| CVE-2024-6912(opens NVD record) | Critical | 9.8 | Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | Jul 22, 2024 |
| CVE-2024-32152(opens NVD record) | Low | 3.1 | A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability. | Jul 22, 2024 |
| CVE-2024-37391(opens NVD record) | High | 7.8 | ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | Jul 22, 2024 |
| CVE-2024-41597(opens NVD record) | Medium | 4.2 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review. | Jul 19, 2024 |
| CVE-2024-38156(opens NVD record) | Medium | 6.1 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jul 19, 2024 |
| CVE-2024-38302(opens NVD record) | Medium | 6.8 | Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | Jul 18, 2024 |
| CVE-2024-30473(opens NVD record) | Medium | 4.9 | Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points. | Jul 18, 2024 |
| CVE-2023-50304(opens NVD record) | High | 7.1 | IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335. | Jul 18, 2024 |
| CVE-2024-40898(opens NVD record) | High | 7.5 | SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. | Jul 18, 2024 |
| CVE-2024-40764(opens NVD record) | High | 7.5 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). | Jul 18, 2024 |
| CVE-2024-29014(opens NVD record) | High | 8.8 | Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update. | Jul 18, 2024 |
| CVE-2024-41011(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We remap the HDP flush registers into this space to allow userspace (CPU or GPU) to flush the HDP when it updates VRAM. However, on systems with >4K pages, we end up exposing PAGE_SIZE of MMIO space. | Jul 18, 2024 |