Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,091 matching · page 983/1262Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-26630(opens NVD record) | High | 7.1 | In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache walk In cachestat, we access the folio from the page cache's xarray to compute its page offset, and check for its dirty and writeback flags. However, we do not hold a reference to the folio before performing these actions, which means the folio can concurrently be released and reused as another folio/page/slab. Get around this altogether by just using xarray's existing machinery for the folio page offsets and dirty/writeback states. This changes behavior for tmpfs files to now always report zeroes in their dirty and writeback counters. This is okay as tmpfs doesn't follow conventional writeback cache behavior: its pages get "cleaned" during swapout, after which they're no longer resident etc. | Mar 13, 2024 |
| CVE-2024-0830(opens NVD record) | Medium | 4.3 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. As a result, they may modify comment form fields and update plugin settings. | Mar 13, 2024 |
| CVE-2024-0829(opens NVD record) | Medium | 4.3 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to invoke those actions. As a result, they may modify comment form fields and update plugin settings. | Mar 13, 2024 |
| CVE-2024-0161(opens NVD record) | High | 7.2 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | Mar 13, 2024 |
| CVE-2024-1979(opens NVD record) | Low | 3.5 | A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk. | Mar 13, 2024 |
| CVE-2023-43043(opens NVD record) | Medium | 5.1 | IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875. | Mar 13, 2024 |
| CVE-2023-38723(opens NVD record) | Medium | 6.4 | IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262192. | Mar 13, 2024 |
| CVE-2023-32335(opens NVD record) | Low | 3.7 | IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075. | Mar 13, 2024 |
| CVE-2023-28517(opens NVD record) | Medium | 5.4 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421. | Mar 13, 2024 |
| CVE-2023-43279(opens NVD record) | Medium | 6.5 | Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. | Mar 12, 2024 |
| CVE-2024-26204(opens NVD record) | High | 7.5 | Outlook for Android Information Disclosure Vulnerability | Mar 12, 2024 |
| CVE-2024-26203(opens NVD record) | High | 7.3 | Azure Data Studio Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26201(opens NVD record) | Medium | 6.6 | Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26199(opens NVD record) | High | 7.8 | Microsoft Office Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26198(opens NVD record) | High | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-26197(opens NVD record) | Medium | 6.5 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Mar 12, 2024 |
| CVE-2024-26190(opens NVD record) | High | 7.5 | Microsoft QUIC Denial of Service Vulnerability | Mar 12, 2024 |
| CVE-2024-26185(opens NVD record) | Medium | 6.5 | Windows Compressed Folder Tampering Vulnerability | Mar 12, 2024 |
| CVE-2024-26182(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26181(opens NVD record) | Medium | 5.5 | Windows Kernel Denial of Service Vulnerability | Mar 12, 2024 |
| CVE-2024-26178(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26177(opens NVD record) | Medium | 5.5 | Windows Kernel Information Disclosure Vulnerability | Mar 12, 2024 |
| CVE-2024-26176(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26174(opens NVD record) | Medium | 5.5 | Windows Kernel Information Disclosure Vulnerability | Mar 12, 2024 |
| CVE-2024-26173(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26170(opens NVD record) | High | 7.8 | Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26169(opens NVD record) | High | 7.8 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26166(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-26165(opens NVD record) | High | 8.8 | Visual Studio Code Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-26164(opens NVD record) | High | 8.8 | Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-26162(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-26161(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-26160(opens NVD record) | Medium | 5.5 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | Mar 12, 2024 |
| CVE-2024-26159(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21451(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21450(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21448(opens NVD record) | Medium | 5.0 | Microsoft Teams for Android Information Disclosure Vulnerability | Mar 12, 2024 |
| CVE-2024-21446(opens NVD record) | High | 7.8 | NTFS Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21445(opens NVD record) | High | 7.0 | Windows USB Print Driver Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21444(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21443(opens NVD record) | High | 7.3 | Windows Kernel Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21442(opens NVD record) | High | 7.8 | Windows USB Print Driver Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21441(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21440(opens NVD record) | High | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21439(opens NVD record) | High | 7.0 | Windows Telephony Server Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21438(opens NVD record) | High | 7.5 | Microsoft AllJoyn API Denial of Service Vulnerability | Mar 12, 2024 |
| CVE-2024-21437(opens NVD record) | High | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21436(opens NVD record) | High | 7.8 | Windows Installer Elevation of Privilege Vulnerability | Mar 12, 2024 |
| CVE-2024-21435(opens NVD record) | High | 8.8 | Windows OLE Remote Code Execution Vulnerability | Mar 12, 2024 |
| CVE-2024-21434(opens NVD record) | High | 7.8 | Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | Mar 12, 2024 |