IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-37379 HIGH 8.1 apache airflow Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connect 2.0%
CVE-2023-36897 HIGH 8.1 microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability 1.7%
CVE-2023-36554 HIGH 8.1 fortinet fortimanager A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requ 0.8%
CVE-2023-35628 HIGH 8.1 microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability 92.8%
CVE-2023-35297 HIGH 8.1 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability 1.1%
CVE-2023-33303 HIGH 8.1 fortinet fortiedr A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request 0.4%
CVE-2023-33170 HIGH 8.1 fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability 2.0%
CVE-2023-33127 HIGH 8.1 microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability 1.9%
CVE-2023-3297 HIGH 8.1 canonical accountsservice In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. 0.3%
CVE-2023-32258 HIGH 8.1 linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an obj 2.5%
CVE-2023-32257 HIGH 8.1 linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations o 2.4%
CVE-2023-29351 HIGH 8.1 microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability 1.8%
CVE-2023-29325 HIGH 8.1 microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability 84.4%
CVE-2023-29032 HIGH 8.1 apache openmeetings An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0 1.1%
CVE-2023-28656 HIGH 8.1 f5 nginx_api_connectivity_manager NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5%
CVE-2023-28288 HIGH 8.1 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 6.2%
CVE-2023-28283 HIGH 8.1 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.0%
CVE-2023-28268 HIGH 8.1 microsoft windows_server_2008 Netlogon RPC Elevation of Privilege Vulnerability 1.5%
CVE-2023-28244 HIGH 8.1 microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability 2.9%
CVE-2023-28220 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 15.0%
CVE-2023-28219 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 15.0%
CVE-2023-26205 HIGH 8.1 fortinet fortiadc An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a spe 0.6%
CVE-2023-25734 HIGH 8.1 mozilla firefox After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resou 0.8%
CVE-2023-25195 HIGH 8.1 apache fineract Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic.  This issue affects Apache Fineract: fr 1.0%
CVE-2023-24908 HIGH 8.1 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.0%