57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36633 | MED 5.4 | fortinet fortimail An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests. | 0.5% | — |
| CVE-2023-36584 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 3.1% | |
| CVE-2023-36387 | MED 5.4 | apache superset An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections. | 0.8% | — |
| CVE-2023-35896 | MED 5.4 | ibm content_navigator IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: | 0.3% | — |
| CVE-2023-35384 | MED 5.4 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2023-35020 | MED 5.4 | ibm sterling_control_center IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874. | 0.5% | — |
| CVE-2023-33846 | MED 5.4 | ibm cics_tx IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional | 0.5% | — |
| CVE-2023-32052 | MED 5.4 | microsoft power_apps Microsoft Power Apps (online) Spoofing Vulnerability | 0.5% | — |
| CVE-2023-30994 | MED 5.4 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138 | 0.2% | — |
| CVE-2023-29247 | MED 5.4 | apache airflow Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. | 1.9% | — |
| CVE-2023-29240 | MED 5.4 | f5 big-iq_centralized_management An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2023-28517 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials | 0.3% | — |
| CVE-2023-26283 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted | 0.4% | — |
| CVE-2023-25603 | MED 5.4 | fortinet fortiadc A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted | 0.4% | — |
| CVE-2023-24921 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2023-24920 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.3% | — |
| CVE-2023-24919 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2023-24896 | MED 5.4 | microsoft dynamics_365 Dynamics 365 Finance Spoofing Vulnerability | 0.7% | — |
| CVE-2023-24891 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2023-24879 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2023-23482 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim | 0.6% | — |
| CVE-2023-23480 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc | 0.4% | — |
| CVE-2023-22868 | MED 5.4 | ibm aspera_faspex IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IB | 0.4% | — |
| CVE-2023-22665 | MED 5.4 | apache jena There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query. | 1.3% | — |
| CVE-2023-21573 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |