57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-44250 | HIGH 8.8 | fortinet fortios An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted | 0.9% | — |
| CVE-2023-42791 | HIGH 8.8 | fortinet fortimanager A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 4.2% | — |
| CVE-2023-42773 | HIGH 8.8 | intel power_gadget Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-41678 | HIGH 8.8 | fortinet fortios A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request. | 1.1% | — |
| CVE-2023-40683 | HIGH 8.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to by | 0.7% | — |
| CVE-2023-40250 | HIGH 8.8 | hancom hcell Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893. | 0.6% | — |
| CVE-2023-40195 | HIGH 8.8 | apache airflow_spark_provider Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that i | 1.9% | — |
| CVE-2023-39913 | HIGH 8.8 | apache uimaj Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommended to upgrade to ver | 1.5% | — |
| CVE-2023-3955 | HIGH 8.8 | kubernetes kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | 3.1% | — |
| CVE-2023-39508 | HIGH 8.8 | apache airflow Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It | 2.6% | — |
| CVE-2023-38581 | HIGH 8.8 | intel power_gadget Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-38186 | HIGH 8.8 | microsoft windows_10_21h2 Windows Mobile Device Management Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2023-38185 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-38181 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 10.8% | — |
| CVE-2023-38169 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-38151 | HIGH 8.8 | microsoft host_integration_server Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2023-38148 | HIGH 8.8 | microsoft windows_10_21h2 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 8.2% | — |
| CVE-2023-38147 | HIGH 8.8 | microsoft windows_10_1507 Windows Miracast Wireless Display Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-38146 | HIGH 8.8 | microsoft windows_11_21h2 Windows Themes Remote Code Execution Vulnerability | 39.5% | — |
| CVE-2023-37933 | HIGH 8.8 | fortinet fortiadc An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTT | 0.3% | — |
| CVE-2023-37931 | HIGH 8.8 | fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via se | 0.8% | — |
| CVE-2023-37415 | HIGH 8.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: | 1.6% | — |
| CVE-2023-36899 | HIGH 8.8 | microsoft .net_framework ASP.NET Elevation of Privilege Vulnerability | 76.7% | — |
| CVE-2023-36882 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36787 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.0% | — |