57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-3467 | HIGH 8.0 | citrix netscaler_application_delivery_controller Privilege Escalation to root administrator (nsroot) | 1.3% | — |
| CVE-2023-29183 | HIGH 8.0 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6. | 1.4% | — |
| CVE-2023-28310 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 25.0% | — |
| CVE-2023-23780 | HIGH 8.0 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests. | 0.8% | — |
| CVE-2023-21778 | HIGH 8.0 | microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-21762 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.6% | — |
| CVE-2023-21745 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.5% | — |
| CVE-2023-20186 | HIGH 8.0 | cisco ios A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an aff | 0.6% | — |
| CVE-2023-20055 | HIGH 8.0 | cisco catalyst_center A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of se | 0.7% | — |
| CVE-2022-49968 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ieee802154/adf7242: defer destroy_workqueue call There is a possible race condition (use-after-free) like below (FREE) | (USE) adf7242_remove | adf7242 | 0.2% | — |
| CVE-2022-45855 | HIGH 8.0 | apache ambari SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | 1.2% | — |
| CVE-2022-45064 | HIGH 8.0 | apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou | 1.1% | — |
| CVE-2022-42896 | HIGH 8.0 | linux linux_kernel There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could | 2.1% | — |
| CVE-2022-42009 | HIGH 8.0 | apache ambari SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | 1.2% | — |
| CVE-2022-41082 | HIGH 8.0 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2022-41079 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-41078 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-39950 | HIGH 8.0 | fortinet fortianalyzer An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege leve | 0.7% | — |
| CVE-2022-38373 | HIGH 8.0 | fortinet fortideceptor An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests wi | 0.5% | — |
| CVE-2022-35851 | HIGH 8.0 | fortinet fortiadc An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted | 0.5% | — |
| CVE-2022-28707 | HIGH 8.0 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility (also referred to as t | 0.6% | — |
| CVE-2022-24533 | HIGH 8.0 | microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability | 5.6% | — |
| CVE-2022-24516 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2022-24477 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-24472 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |