57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36764 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2023-3676 | HIGH 8.8 | kubernetes kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | 12.7% | — |
| CVE-2023-36577 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36560 | HIGH 8.8 | microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2023-36556 | HIGH 8.8 | fortinet fortimail An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTP | 0.8% | — |
| CVE-2023-36549 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req | 2.1% | — |
| CVE-2023-36542 | HIGH 8.8 | apache nifi Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution in | 1.9% | — |
| CVE-2023-36437 | HIGH 8.8 | microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-36423 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-36419 | HIGH 8.8 | microsoft azure_hdinsight Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-36415 | HIGH 8.8 | microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-36414 | HIGH 8.8 | microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-36402 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2023-36400 | HIGH 8.8 | microsoft windows_10_1507 Windows HMAC Key Derivation Elevation of Privilege Vulnerability | 4.3% | — |
| CVE-2023-36025 | HIGH 8.8 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 88.2% | |
| CVE-2023-36017 | HIGH 8.8 | microsoft windows_10_1507 Windows Scripting Engine Memory Corruption Vulnerability | 25.3% | — |
| CVE-2023-36006 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2023-35641 | HIGH 8.8 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 7.2% | — |
| CVE-2023-35639 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2023-35630 | HIGH 8.8 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 6.1% | — |
| CVE-2023-35387 | HIGH 8.8 | microsoft windows_10_1507 Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-35381 | HIGH 8.8 | microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2023-35368 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2023-35364 | HIGH 8.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35333 | HIGH 8.8 | microsoft pandocupload MediaWiki PandocUpload Extension Remote Code Execution Vulnerability | 1.2% | — |