Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,091 matching · page 975/1262Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-47541(opens NVD record) | Medium | 6.7 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all versions, FortiSandbox 2.3 all versions, FortiSandbox 2.2 all versions, FortiSandbox 2.1 all versions, FortiSandbox 2.0 all versions allows attacker to execute unauthorized code or commands via CLI. | Apr 9, 2024 |
| CVE-2023-47540(opens NVD record) | Medium | 6.7 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.0.5 through 3.0.7 allows attacker to execute unauthorized code or commands via CLI. | Apr 9, 2024 |
| CVE-2023-45590(opens NVD record) | Critical | 9.6 | An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website | Apr 9, 2024 |
| CVE-2023-41677(opens NVD record) | High | 7.5 | A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or commands via targeted social engineering attack | Apr 9, 2024 |
| CVE-2024-2975(opens NVD record) | High | 8.8 | A race condition was identified through which privilege escalation was possible in certain configurations. | Apr 9, 2024 |
| CVE-2024-23084(opens NVD record) | High | 7.5 | Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-23081(opens NVD record) | Low | 3.3 | ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-23079(opens NVD record) | Medium | 6.2 | JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-22949(opens NVD record) | Critical | 9.1 | JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-0083(opens NVD record) | Medium | 6.5 | NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and information disclosure. | Apr 8, 2024 |
| CVE-2024-0082(opens NVD record) | High | 8.2 | NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information disclosure, and data tampering | Apr 8, 2024 |
| CVE-2024-23086(opens NVD record) | Critical | 9.8 | Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-23085(opens NVD record) | High | 7.5 | Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-23078(opens NVD record) | Critical | 9.1 | JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-23082(opens NVD record) | Unscored | — | ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification. | Apr 8, 2024 |
| CVE-2024-27897(opens NVD record) | High | 7.5 | Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2024-27896(opens NVD record) | High | 7.5 | Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity. | Apr 8, 2024 |
| CVE-2024-27895(opens NVD record) | High | 7.5 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | Apr 8, 2024 |
| CVE-2024-26811(opens NVD record) | Critical | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should validate payload size of ipc response from ksmbd.mountd to avoid memory overrun or slab-out-of-bounds. This patch validate 3 ipc response that has payload. | Apr 8, 2024 |
| CVE-2023-52386(opens NVD record) | High | 7.5 | Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52385(opens NVD record) | Medium | 6.2 | Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52364(opens NVD record) | Medium | 6.3 | Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write. | Apr 8, 2024 |
| CVE-2023-52554(opens NVD record) | Medium | 6.5 | Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52553(opens NVD record) | High | 7.4 | Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52552(opens NVD record) | High | 7.5 | Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52551(opens NVD record) | Medium | 5.3 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52550(opens NVD record) | High | 7.5 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52549(opens NVD record) | High | 7.5 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52546(opens NVD record) | High | 7.5 | Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52545(opens NVD record) | High | 7.5 | Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52544(opens NVD record) | Medium | 4.3 | Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52543(opens NVD record) | Medium | 6.2 | Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52542(opens NVD record) | Medium | 6.5 | Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52541(opens NVD record) | High | 7.5 | Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52540(opens NVD record) | High | 7.5 | Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52539(opens NVD record) | High | 7.5 | Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 8, 2024 |
| CVE-2023-52538(opens NVD record) | Critical | 9.1 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52537(opens NVD record) | High | 7.5 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52388(opens NVD record) | High | 7.5 | Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2023-52359(opens NVD record) | High | 7.5 | Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 8, 2024 |
| CVE-2024-30418(opens NVD record) | High | 7.5 | Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 7, 2024 |
| CVE-2024-30417(opens NVD record) | High | 7.5 | Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 7, 2024 |
| CVE-2024-30416(opens NVD record) | High | 7.5 | Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 7, 2024 |
| CVE-2023-52717(opens NVD record) | Medium | 5.3 | Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 7, 2024 |
| CVE-2023-52716(opens NVD record) | High | 7.5 | Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 7, 2024 |
| CVE-2023-52715(opens NVD record) | High | 7.5 | The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability. | Apr 7, 2024 |
| CVE-2023-52714(opens NVD record) | High | 7.5 | Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 7, 2024 |
| CVE-2023-52713(opens NVD record) | High | 7.7 | Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | Apr 7, 2024 |
| CVE-2024-30415(opens NVD record) | Critical | 9.1 | Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability. | Apr 7, 2024 |
| CVE-2024-30414(opens NVD record) | High | 7.5 | Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Apr 7, 2024 |