Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,091 matching · page 956/1262Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-30312(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 15, 2024 |
| CVE-2024-30311(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 15, 2024 |
| CVE-2024-30310(opens NVD record) | High | 7.8 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 15, 2024 |
| CVE-2024-30284(opens NVD record) | High | 7.8 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 15, 2024 |
| CVE-2024-31483(opens NVD record) | Medium | 4.9 | An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system. | May 14, 2024 |
| CVE-2024-31482(opens NVD record) | Medium | 5.3 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point. | May 14, 2024 |
| CVE-2024-31481(opens NVD record) | Medium | 5.3 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service. | May 14, 2024 |
| CVE-2024-31480(opens NVD record) | Medium | 5.3 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service. | May 14, 2024 |
| CVE-2024-31479(opens NVD record) | Medium | 5.3 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service. | May 14, 2024 |
| CVE-2024-31478(opens NVD record) | Medium | 5.3 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point. | May 14, 2024 |
| CVE-2024-31477(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31476(opens NVD record) | High | 7.2 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31475(opens NVD record) | High | 8.2 | There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point. | May 14, 2024 |
| CVE-2024-31474(opens NVD record) | High | 8.2 | There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point | May 14, 2024 |
| CVE-2024-31473(opens NVD record) | Critical | 9.8 | There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31472(opens NVD record) | Critical | 9.8 | There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31471(opens NVD record) | Critical | 9.8 | There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31470(opens NVD record) | Critical | 9.8 | There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31469(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31468(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31467(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-31466(opens NVD record) | Critical | 9.8 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. | May 14, 2024 |
| CVE-2024-4562(opens NVD record) | Medium | 5.4 | In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality. Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery. | May 14, 2024 |
| CVE-2024-4561(opens NVD record) | Medium | 4.2 | In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server. | May 14, 2024 |
| CVE-2024-31491(opens NVD record) | High | 8.8 | A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests. | May 14, 2024 |
| CVE-2024-31488(opens NVD record) | Medium | 6.8 | An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests. | May 14, 2024 |
| CVE-2024-30059(opens NVD record) | Medium | 6.1 | Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | May 14, 2024 |
| CVE-2024-30054(opens NVD record) | Medium | 6.5 | Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | May 14, 2024 |
| CVE-2024-30053(opens NVD record) | Medium | 6.5 | Azure Migrate Cross-Site Scripting Vulnerability | May 14, 2024 |
| CVE-2024-30051(opens NVD record) | High | 7.8 | Windows DWM Core Library Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30050(opens NVD record) | Medium | 5.4 | Windows Mark of the Web Security Feature Bypass Vulnerability | May 14, 2024 |
| CVE-2024-30049(opens NVD record) | High | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30048(opens NVD record) | High | 7.6 | Dynamics 365 Customer Insights Spoofing Vulnerability | May 14, 2024 |
| CVE-2024-30047(opens NVD record) | High | 7.6 | Dynamics 365 Customer Insights Spoofing Vulnerability | May 14, 2024 |
| CVE-2024-30046(opens NVD record) | Medium | 5.9 | Visual Studio Denial of Service Vulnerability | May 14, 2024 |
| CVE-2024-30045(opens NVD record) | Medium | 6.3 | .NET and Visual Studio Remote Code Execution Vulnerability | May 14, 2024 |
| CVE-2024-30044(opens NVD record) | High | 7.2 | Microsoft SharePoint Server Remote Code Execution Vulnerability | May 14, 2024 |
| CVE-2024-30043(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Information Disclosure Vulnerability | May 14, 2024 |
| CVE-2024-30042(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | May 14, 2024 |
| CVE-2024-30041(opens NVD record) | Medium | 5.4 | Microsoft Bing Search Spoofing Vulnerability | May 14, 2024 |
| CVE-2024-30040(opens NVD record) | High | 8.8 | Windows MSHTML Platform Security Feature Bypass Vulnerability | May 14, 2024 |
| CVE-2024-30039(opens NVD record) | Medium | 5.5 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | May 14, 2024 |
| CVE-2024-30038(opens NVD record) | High | 7.8 | Win32k Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30037(opens NVD record) | Medium | 5.5 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30036(opens NVD record) | Medium | 6.5 | Windows Deployment Services Information Disclosure Vulnerability | May 14, 2024 |
| CVE-2024-30035(opens NVD record) | High | 7.8 | Windows DWM Core Library Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30034(opens NVD record) | Medium | 5.5 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | May 14, 2024 |
| CVE-2024-30033(opens NVD record) | High | 7.0 | Windows Search Service Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30032(opens NVD record) | High | 7.8 | Windows DWM Core Library Elevation of Privilege Vulnerability | May 14, 2024 |
| CVE-2024-30031(opens NVD record) | High | 7.8 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | May 14, 2024 |