57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-37379 | HIGH 8.1 | apache airflow Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connect | 2.0% | — |
| CVE-2023-36897 | HIGH 8.1 | microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability | 1.7% | — |
| CVE-2023-36554 | HIGH 8.1 | fortinet fortimanager A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requ | 0.8% | — |
| CVE-2023-35628 | HIGH 8.1 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 92.8% | — |
| CVE-2023-35297 | HIGH 8.1 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-33303 | HIGH 8.1 | fortinet fortiedr A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request | 0.4% | — |
| CVE-2023-33170 | HIGH 8.1 | fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2023-33127 | HIGH 8.1 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2023-3297 | HIGH 8.1 | canonical accountsservice In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | 0.3% | — |
| CVE-2023-32258 | HIGH 8.1 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an obj | 2.5% | — |
| CVE-2023-32257 | HIGH 8.1 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations o | 2.4% | — |
| CVE-2023-29351 | HIGH 8.1 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2023-29325 | HIGH 8.1 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 84.4% | — |
| CVE-2023-29032 | HIGH 8.1 | apache openmeetings An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0 | 1.1% | — |
| CVE-2023-28656 | HIGH 8.1 | f5 nginx_api_connectivity_manager NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2023-28288 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 6.2% | — |
| CVE-2023-28283 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-28268 | HIGH 8.1 | microsoft windows_server_2008 Netlogon RPC Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-28244 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2023-28220 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 15.0% | — |
| CVE-2023-28219 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 15.0% | — |
| CVE-2023-26205 | HIGH 8.1 | fortinet fortiadc An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a spe | 0.6% | — |
| CVE-2023-25734 | HIGH 8.1 | mozilla firefox After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resou | 0.8% | — |
| CVE-2023-25195 | HIGH 8.1 | apache fineract Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic. This issue affects Apache Fineract: fr | 1.0% | — |
| CVE-2023-24908 | HIGH 8.1 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.0% | — |