Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
85,954 matching · page 383/1720Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-24066(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24064(opens NVD record) | High | 8.1 | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24061(opens NVD record) | High | 7.8 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. | Mar 11, 2025 |
| CVE-2025-24059(opens NVD record) | High | 7.8 | Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24057(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24056(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24055(opens NVD record) | Medium | 4.3 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | Mar 11, 2025 |
| CVE-2025-24054(opens NVD record) | Medium | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Mar 11, 2025 |
| CVE-2025-24051(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24050(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24049(opens NVD record) | High | 8.4 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24048(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24046(opens NVD record) | High | 7.8 | Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24045(opens NVD record) | High | 8.1 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24044(opens NVD record) | High | 7.8 | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24043(opens NVD record) | High | 7.5 | Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24035(opens NVD record) | High | 8.1 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-21247(opens NVD record) | Medium | 4.3 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | Mar 11, 2025 |
| CVE-2025-21199(opens NVD record) | Medium | 6.7 | Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-21180(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2024-56338(opens NVD record) | Medium | 4.8 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Mar 11, 2025 |
| CVE-2025-22454(opens NVD record) | High | 7.8 | Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | Mar 11, 2025 |
| CVE-2024-55597(opens NVD record) | Medium | 5.5 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests. | Mar 11, 2025 |
| CVE-2024-55592(opens NVD record) | Low | 3.8 | An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to perform unauthorized operations on incidents via crafted HTTP requests. | Mar 11, 2025 |
| CVE-2024-55590(opens NVD record) | High | 8.8 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands. | Mar 11, 2025 |
| CVE-2024-54026(opens NVD record) | Medium | 4.3 | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Mar 11, 2025 |
| CVE-2024-54018(opens NVD record) | High | 7.2 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. | Mar 11, 2025 |
| CVE-2024-52961(opens NVD record) | High | 8.8 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests. | Mar 11, 2025 |
| CVE-2024-52960(opens NVD record) | Medium | 4.3 | A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests. | Mar 11, 2025 |
| CVE-2024-46663(opens NVD record) | Medium | 6.7 | A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | Mar 11, 2025 |
| CVE-2024-45328(opens NVD record) | High | 7.8 | An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu. | Mar 11, 2025 |
| CVE-2024-45324(opens NVD record) | High | 7.2 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands. | Mar 11, 2025 |
| CVE-2024-33501(opens NVD record) | Medium | 4.2 | Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests. | Mar 11, 2025 |
| CVE-2024-32123(opens NVD record) | Medium | 6.7 | Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 through 5.2.10 and 5.0.0 through 5.0.12 and 4.3.4 through 4.3.8 allows attacker to execute unauthorized code or commands via crafted CLI requests. | Mar 11, 2025 |
| CVE-2023-48790(opens NVD record) | High | 7.5 | A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests. | Mar 11, 2025 |
| CVE-2023-42784(opens NVD record) | Medium | 5.6 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests. | Mar 11, 2025 |
| CVE-2023-40723(opens NVD record) | High | 8.1 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 allows attacker to execute unauthorized code or commands via api request. | Mar 11, 2025 |
| CVE-2023-37933(opens NVD record) | High | 8.8 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests. | Mar 11, 2025 |
| CVE-2024-54085(opens NVD record) | Critical | 9.8 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | Mar 11, 2025 |
| CVE-2024-49823(opens NVD record) | Medium | 6.5 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests. | Mar 11, 2025 |
| CVE-2024-41760(opens NVD record) | Low | 3.7 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations. | Mar 11, 2025 |
| CVE-2024-22340(opens NVD record) | Medium | 6.5 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | Mar 11, 2025 |
| CVE-2025-24813(opens NVD record) | Critical | 9.8 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue. | Mar 10, 2025 |
| CVE-2024-52905(opens NVD record) | Low | 2.7 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user. | Mar 10, 2025 |
| CVE-2024-47109(opens NVD record) | Medium | 5.3 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system. | Mar 10, 2025 |
| CVE-2025-26643(opens NVD record) | Medium | 5.4 | The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | Mar 7, 2025 |
| CVE-2025-0162(opens NVD record) | High | 7.1 | IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | Mar 7, 2025 |
| CVE-2023-43052(opens NVD record) | Medium | 5.3 | IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. | Mar 7, 2025 |
| CVE-2023-35894(opens NVD record) | Medium | 5.4 | IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. | Mar 7, 2025 |
| CVE-2025-26331(opens NVD record) | High | 7.8 | Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | Mar 7, 2025 |