Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
38,646 matching · page 410/773Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2024-49082(opens NVD record) | Medium | 6.8 | Windows File Explorer Information Disclosure Vulnerability | Dec 12, 2024 |
| CVE-2024-49081(opens NVD record) | Medium | 6.6 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49080(opens NVD record) | High | 8.8 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49079(opens NVD record) | High | 7.8 | Input Method Editor (IME) Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49078(opens NVD record) | Medium | 6.8 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49077(opens NVD record) | Medium | 6.8 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49076(opens NVD record) | High | 7.8 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49075(opens NVD record) | High | 7.5 | Windows Remote Desktop Services Denial of Service Vulnerability | Dec 12, 2024 |
| CVE-2024-49074(opens NVD record) | High | 7.8 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49073(opens NVD record) | Medium | 6.8 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49072(opens NVD record) | High | 7.8 | Windows Task Scheduler Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49070(opens NVD record) | High | 7.4 | Microsoft SharePoint Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49069(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49068(opens NVD record) | High | 8.2 | Microsoft SharePoint Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49065(opens NVD record) | Medium | 5.5 | Microsoft Office Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49064(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Information Disclosure Vulnerability | Dec 12, 2024 |
| CVE-2024-49063(opens NVD record) | High | 8.4 | Microsoft/Muzic Remote Code Execution Vulnerability | Dec 12, 2024 |
| CVE-2024-49062(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Information Disclosure Vulnerability | Dec 12, 2024 |
| CVE-2024-49059(opens NVD record) | High | 7.0 | Microsoft Office Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-49057(opens NVD record) | High | 8.1 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | Dec 12, 2024 |
| CVE-2024-43600(opens NVD record) | High | 7.8 | Microsoft Office Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-43594(opens NVD record) | High | 7.3 | Microsoft System Center Elevation of Privilege Vulnerability | Dec 12, 2024 |
| CVE-2024-37401(opens NVD record) | High | 7.5 | An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service. | Dec 12, 2024 |
| CVE-2024-37377(opens NVD record) | High | 7.5 | A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service. | Dec 12, 2024 |
| CVE-2024-9845(opens NVD record) | High | 7.8 | Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation. | Dec 11, 2024 |
| CVE-2024-8496(opens NVD record) | High | 7.8 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. | Dec 11, 2024 |
| CVE-2024-11598(opens NVD record) | High | 7.8 | Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation. | Dec 11, 2024 |
| CVE-2024-11597(opens NVD record) | High | 7.8 | Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation. | Dec 11, 2024 |
| CVE-2024-10251(opens NVD record) | High | 7.8 | Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation. | Dec 11, 2024 |
| CVE-2024-51460(opens NVD record) | Medium | 4.3 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. | Dec 11, 2024 |
| CVE-2023-23472(opens NVD record) | Low | 3.1 | IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | Dec 11, 2024 |
| CVE-2024-53292(opens NVD record) | High | 7.2 | Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable component with privileges of the compromised account. | Dec 11, 2024 |
| CVE-2024-53290(opens NVD record) | High | 8.4 | Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Command execution | Dec 11, 2024 |
| CVE-2024-53289(opens NVD record) | High | 7.8 | Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | Dec 11, 2024 |
| CVE-2024-52537(opens NVD record) | Medium | 6.3 | Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | Dec 11, 2024 |
| CVE-2024-11053(opens NVD record) | Low | 3.4 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. | Dec 11, 2024 |
| CVE-2023-37395(opens NVD record) | Low | 2.5 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. | Dec 11, 2024 |
| CVE-2024-35117(opens NVD record) | Medium | 4.4 | IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. | Dec 11, 2024 |
| CVE-2024-53959(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53956(opens NVD record) | High | 7.8 | Premiere Pro versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53955(opens NVD record) | High | 7.8 | Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53954(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53953(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53952(opens NVD record) | Medium | 5.5 | InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-53951(opens NVD record) | Medium | 5.5 | InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-52997(opens NVD record) | High | 7.8 | Photoshop Desktop versions 26.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-52990(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to manipulate memory in such a way that they could execute code under the privileges of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-52989(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-52988(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |
| CVE-2024-52987(opens NVD record) | High | 7.8 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 10, 2024 |