57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-31469 | HIGH 8.8 | apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by | 1.1% | — |
| CVE-2023-31038 | HIGH 8.8 | apache log4cxx SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx i | 1.6% | — |
| CVE-2023-3079 | HIGH 8.8 | apple macos Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 32.1% | |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0.9% | — |
| CVE-2023-29373 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29372 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29362 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-29328 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-29181 | HIGH 8.8 | fortinet fortios A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 thro | 0.7% | — |
| CVE-2023-28983 | HIGH 8.8 | juniper junos_os_evolved An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects J | 1.5% | — |
| CVE-2023-28935 | HIGH 8.8 | apache unstructured_information_management_architecture ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA | 2.9% | — |
| CVE-2023-28754 | HIGH 8.8 | apache shardingsphere Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML c | 1.5% | — |
| CVE-2023-28737 | HIGH 8.8 | intel aptio_v_uefi_firmware_integrator_tools Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28508 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process. | 0.9% | — |
| CVE-2023-28506 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided | 0.9% | — |
| CVE-2023-28505 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the lengt | 0.8% | — |
| CVE-2023-28353 | HIGH 8.8 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, enabling a variety of different exploitation paths including code execution. It | 1.4% | — |
| CVE-2023-28349 | HIGH 8.8 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. | 1.2% | — |
| CVE-2023-28297 | HIGH 8.8 | microsoft windows_10_1607 Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-28275 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-28243 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-28240 | HIGH 8.8 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-28231 | HIGH 8.8 | microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability | 36.9% | — |
| CVE-2023-27604 | HIGH 8.8 | apache airflow_sqoop_provider Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, | 1.7% | — |