IT
57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.411 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-35322 HIGH 8.8 microsoft windows_server_2008 Windows Deployment Services Remote Code Execution Vulnerability 1.4%
CVE-2023-35315 HIGH 8.8 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability 0.7%
CVE-2023-35311 HIGH 8.8 microsoft 365_apps Microsoft Outlook Security Feature Bypass Vulnerability 15.5%
CVE-2023-35303 HIGH 8.8 microsoft windows_10_1507 USB Audio Class System Driver Remote Code Execution Vulnerability 1.5%
CVE-2023-35302 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.4%
CVE-2023-35300 HIGH 8.8 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.4%
CVE-2023-34989 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1%
CVE-2023-34988 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1%
CVE-2023-34987 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1%
CVE-2023-34986 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1%
CVE-2023-34985 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1%
CVE-2023-34468 HIGH 8.8 apache nifi The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates th 61.9%
CVE-2023-33160 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 4.3%
CVE-2023-33159 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 1.3%
CVE-2023-33157 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability 38.2%
CVE-2023-33136 HIGH 8.8 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.7%
CVE-2023-33134 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 2.6%
CVE-2023-33131 HIGH 8.8 microsoft office Microsoft Outlook Remote Code Execution Vulnerability 5.7%
CVE-2023-32336 HIGH 8.8 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. 1.4%
CVE-2023-32200 HIGH 8.8 apache jena There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0. 1.5%
CVE-2023-32049 HIGH 8.8 microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability 4.2%
CVE-2023-32038 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-32031 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 81.5%
CVE-2023-32009 HIGH 8.8 microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability 0.4%
CVE-2023-32007 HIGH 8.8 apache spark ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL 76.0%