Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
82,478 matching · page 366/1650Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-39381(opens NVD record) | High | 7.8 | After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-39380(opens NVD record) | High | 7.8 | After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-34121(opens NVD record) | High | 7.8 | Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-41873(opens NVD record) | Medium | 5.5 | Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-41872(opens NVD record) | Medium | 5.5 | Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-41871(opens NVD record) | Medium | 5.5 | Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-41870(opens NVD record) | Medium | 5.5 | Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-39377(opens NVD record) | High | 7.8 | Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 13, 2024 |
| CVE-2024-43180(opens NVD record) | Medium | 4.3 | IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | Sep 13, 2024 |
| CVE-2024-8751(opens NVD record) | High | 7.5 | A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack. | Sep 12, 2024 |
| CVE-2024-20430(opens NVD record) | High | 7.3 | A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. This vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged attacker could exploit this vulnerability by placing both malicious configuration files and malicious DLL files on an affected system, which would read and execute the files when Cisco Meraki SM launches on startup. A successful exploit could allow the attacker to execute arbitrary code on the affected system with SYSTEM privileges. | Sep 12, 2024 |
| CVE-2024-45383(opens NVD record) | Medium | 5.0 | A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability. | Sep 12, 2024 |
| CVE-2024-45182(opens NVD record) | Medium | 5.5 | An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service. | Sep 12, 2024 |
| CVE-2024-45181(opens NVD record) | High | 7.8 | An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption. | Sep 12, 2024 |
| CVE-2024-34336(opens NVD record) | Medium | 5.3 | User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality. | Sep 12, 2024 |
| CVE-2024-34335(opens NVD record) | Medium | 6.1 | ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page. | Sep 12, 2024 |
| CVE-2024-34334(opens NVD record) | High | 7.5 | ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function. | Sep 12, 2024 |
| CVE-2024-6658(opens NVD record) | High | 8.4 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From 7.2.49.0 to 7.2.54.11 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.11 and all prior versions ECS All prior versions to 7.2.60.0 (inclusive) | Sep 12, 2024 |
| CVE-2024-28991(opens NVD record) | Critical | 9.0 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution. | Sep 12, 2024 |
| CVE-2024-28990(opens NVD record) | Medium | 6.3 | SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities. | Sep 12, 2024 |
| CVE-2022-26322(opens NVD record) | Medium | 4.9 | Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200. | Sep 12, 2024 |
| CVE-2021-38133(opens NVD record) | High | 7.4 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | Sep 12, 2024 |
| CVE-2021-38132(opens NVD record) | Medium | 5.3 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | Sep 12, 2024 |
| CVE-2021-38131(opens NVD record) | Medium | 5.4 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. | Sep 12, 2024 |
| CVE-2021-22533(opens NVD record) | Medium | 6.5 | Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000. | Sep 12, 2024 |
| CVE-2021-22532(opens NVD record) | High | 7.6 | Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000. | Sep 12, 2024 |
| CVE-2021-22503(opens NVD record) | Medium | 5.4 | Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000. | Sep 12, 2024 |
| CVE-2024-38222(opens NVD record) | Medium | 6.5 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Sep 12, 2024 |
| CVE-2024-37397(opens NVD record) | High | 8.2 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | Sep 12, 2024 |
| CVE-2024-34785(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-34783(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-34779(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32848(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32846(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32845(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32843(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32842(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-32840(opens NVD record) | High | 7.2 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-29847(opens NVD record) | Critical | 9.8 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | Sep 12, 2024 |
| CVE-2024-7890(opens NVD record) | High | 7.3 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | Sep 11, 2024 |
| CVE-2024-7889(opens NVD record) | High | 7.3 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | Sep 11, 2024 |
| CVE-2024-8691(opens NVD record) | High | 7.1 | A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker. | Sep 11, 2024 |
| CVE-2024-8690(opens NVD record) | Medium | 4.4 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | Sep 11, 2024 |
| CVE-2024-8688(opens NVD record) | Medium | 4.4 | An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall. | Sep 11, 2024 |
| CVE-2024-8687(opens NVD record) | High | 7.1 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so. | Sep 11, 2024 |
| CVE-2024-8686(opens NVD record) | High | 7.2 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | Sep 11, 2024 |
| CVE-2024-44577(opens NVD record) | High | 8.8 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. | Sep 11, 2024 |
| CVE-2024-44575(opens NVD record) | Low | 3.7 | RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session. | Sep 11, 2024 |
| CVE-2024-44574(opens NVD record) | High | 8.8 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. | Sep 11, 2024 |
| CVE-2024-44573(opens NVD record) | Medium | 4.7 | A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Sep 11, 2024 |