58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-38738 | MED 6.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of s | 0.5% | — |
| CVE-2023-38729 | MED 6.8 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT. | 0.6% | — |
| CVE-2023-36697 | MED 6.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2023-35629 | MED 6.8 | microsoft windows_10_1507 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-35332 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Protocol Security Feature Bypass | 0.5% | — |
| CVE-2023-33153 | MED 6.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-32043 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-30576 | MED 6.8 | apache guacamole Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process. | 1.1% | — |
| CVE-2023-28972 | MED 6.8 | juniper junos An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed f | 0.4% | — |
| CVE-2023-28270 | MED 6.8 | microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-28235 | MED 6.8 | microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-28005 | MED 6.8 | trendmicro trend_micro_endpoint_encryption A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to o | 0.2% | — |
| CVE-2023-26211 | MED 6.8 | fortinet fortisoar An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | 0.7% | — |
| CVE-2023-26206 | MED 6.8 | fortinet fortinac An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the | 0.5% | — |
| CVE-2023-24023 | MED 6.8 | bluetooth bluetooth_core_specification Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live | 1.3% | — |
| CVE-2023-23779 | MED 6.8 | fortinet fortiweb Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthor | 1.3% | — |
| CVE-2023-21694 | MED 6.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21563 | MED 6.8 | microsoft windows_10_1607 BitLocker Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2023-20857 | MED 6.8 | vmware workspace_one_content VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | 0.9% | — |
| CVE-2023-20116 | MED 6.8 | cisco unified_communications_manager A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a d | 0.6% | — |
| CVE-2023-20100 | MED 6.8 | cisco ios_xe A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial | 0.8% | — |
| CVE-2023-20081 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a | 0.7% | — |
| CVE-2023-20042 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected | 0.7% | — |
| CVE-2023-2002 | MED 6.8 | debian debian_linux A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, inte | 1.5% | — |
| CVE-2023-1079 | MED 6.8 | linux linux_kernel A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device, which advertises itself as an Asus device. Similarly to the previous known CVE-2023-25012, but in asus devi | 0.5% | — |