Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
63,182 matching · page 997/1264Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-21341(opens NVD record) | Medium | 6.8 | Windows Kernel Remote Code Execution Vulnerability | Feb 13, 2024 |
| CVE-2024-21340(opens NVD record) | Medium | 4.6 | Windows Kernel Information Disclosure Vulnerability | Feb 13, 2024 |
| CVE-2024-21339(opens NVD record) | Medium | 6.4 | Windows USB Generic Parent Driver Remote Code Execution Vulnerability | Feb 13, 2024 |
| CVE-2024-21338(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Feb 13, 2024 |
| CVE-2024-21329(opens NVD record) | High | 7.3 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Feb 13, 2024 |
| CVE-2024-21328(opens NVD record) | High | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | Feb 13, 2024 |
| CVE-2024-21327(opens NVD record) | High | 7.6 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | Feb 13, 2024 |
| CVE-2024-21315(opens NVD record) | High | 7.8 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | Feb 13, 2024 |
| CVE-2024-21304(opens NVD record) | Medium | 4.1 | Trusted Compute Base Elevation of Privilege Vulnerability | Feb 13, 2024 |
| CVE-2024-20695(opens NVD record) | Medium | 5.7 | Skype for Business Information Disclosure Vulnerability | Feb 13, 2024 |
| CVE-2024-20684(opens NVD record) | Medium | 6.5 | Windows Hyper-V Denial of Service Vulnerability | Feb 13, 2024 |
| CVE-2024-20679(opens NVD record) | Medium | 6.5 | Azure Stack Hub Spoofing Vulnerability | Feb 13, 2024 |
| CVE-2024-20673(opens NVD record) | High | 7.8 | Microsoft Office Remote Code Execution Vulnerability | Feb 13, 2024 |
| CVE-2024-20667(opens NVD record) | High | 7.5 | Azure DevOps Server Remote Code Execution Vulnerability | Feb 13, 2024 |
| CVE-2023-6516(opens NVD record) | High | 7.5 | To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1. | Feb 13, 2024 |
| CVE-2023-5680(opens NVD record) | Medium | 5.3 | If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | Feb 13, 2024 |
| CVE-2023-5679(opens NVD record) | High | 7.5 | A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | Feb 13, 2024 |
| CVE-2023-5517(opens NVD record) | High | 7.5 | A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | Feb 13, 2024 |
| CVE-2023-4408(opens NVD record) | High | 7.5 | The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | Feb 13, 2024 |
| CVE-2023-6072(opens NVD record) | Medium | 4.6 | A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard. | Feb 13, 2024 |
| CVE-2024-22454(opens NVD record) | High | 8.8 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change | Feb 13, 2024 |
| CVE-2024-22445(opens NVD record) | High | 7.2 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. | Feb 13, 2024 |
| CVE-2024-22024(opens NVD record) | High | 8.3 | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication. | Feb 13, 2024 |
| CVE-2024-1454(opens NVD record) | Low | 3.4 | The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment. | Feb 12, 2024 |
| CVE-2024-1459(opens NVD record) | Medium | 5.3 | A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories. | Feb 12, 2024 |
| CVE-2024-25110(opens NVD record) | Critical | 9.8 | The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability. | Feb 12, 2024 |
| CVE-2022-22506(opens NVD record) | Medium | 4.6 | IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293. | Feb 12, 2024 |
| CVE-2024-22230(opens NVD record) | Medium | 6.4 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser. | Feb 12, 2024 |
| CVE-2024-22228(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | Feb 12, 2024 |
| CVE-2024-22227(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges. | Feb 12, 2024 |
| CVE-2024-22226(opens NVD record) | Low | 3.3 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges. | Feb 12, 2024 |
| CVE-2024-22225(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | Feb 12, 2024 |
| CVE-2024-22224(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | Feb 12, 2024 |
| CVE-2024-22223(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. | Feb 12, 2024 |
| CVE-2024-22222(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. | Feb 12, 2024 |
| CVE-2024-22221(opens NVD record) | Medium | 4.5 | Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information. | Feb 12, 2024 |
| CVE-2024-0170(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | Feb 12, 2024 |
| CVE-2024-0169(opens NVD record) | Medium | 5.7 | Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | Feb 12, 2024 |
| CVE-2024-0168(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges. | Feb 12, 2024 |
| CVE-2024-0167(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges. | Feb 12, 2024 |
| CVE-2024-0166(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges. | Feb 12, 2024 |
| CVE-2024-0165(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | Feb 12, 2024 |
| CVE-2024-0164(opens NVD record) | High | 7.8 | Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges. | Feb 12, 2024 |
| CVE-2022-34311(opens NVD record) | Medium | 4.3 | IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials. IBM X-Force ID: 229446. | Feb 12, 2024 |
| CVE-2022-34309(opens NVD record) | Medium | 5.9 | IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229440. | Feb 12, 2024 |
| CVE-2022-38714(opens NVD record) | Medium | 4.9 | IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060. | Feb 12, 2024 |
| CVE-2022-34310(opens NVD record) | Medium | 5.9 | IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229441. | Feb 12, 2024 |
| CVE-2023-6681(opens NVD record) | Medium | 5.3 | A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack. | Feb 12, 2024 |
| CVE-2024-1062(opens NVD record) | Medium | 5.5 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. | Feb 12, 2024 |
| CVE-2024-1151(opens NVD record) | Medium | 5.5 | A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues. | Feb 11, 2024 |