IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-40185 MED 6.5 shescape_project shescape shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections 0.7% —
CVE-2023-40037 MED 6.5 apache nifi Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass 2.1% —
CVE-2023-38254 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 1.6% —
CVE-2023-38187 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.8% —
CVE-2023-38157 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 2.5% —
CVE-2023-38131 MED 6.5 intel unison_software Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. 0.7% —
CVE-2023-37935 MED 6.5 fortinet fortios A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET req 0.9% —
CVE-2023-37932 MED 6.5 fortinet fortivoice An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or 0.6% —
CVE-2023-36913 MED 6.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 1.7% —
CVE-2023-36909 MED 6.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.1% —
CVE-2023-36908 MED 6.5 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 1.0% —
CVE-2023-36894 MED 6.5 microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability 2.1% —
CVE-2023-36893 MED 6.5 microsoft 365_apps Microsoft Outlook Spoofing Vulnerability 2.2% —
CVE-2023-36890 MED 6.5 microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability 1.9% —
CVE-2023-36871 MED 6.5 microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability 1.2% —
CVE-2023-36868 MED 6.5 microsoft azure_service_fabric Azure Service Fabric on Windows Information Disclosure Vulnerability 0.7% —
CVE-2023-36850 MED 6.5 juniper junos An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Management(CFM) module of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an adjacent attacker on the local broadcast 0.3% —
CVE-2023-36849 MED 6.5 juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When a malf 0.3% —
CVE-2023-36848 MED 6.5 juniper junos An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Wh 0.3% —
CVE-2023-36842 MED 6.5 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service 0.3% —
CVE-2023-36839 MED 6.5 juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial 0.3% —
CVE-2023-36834 MED 6.5 juniper junos An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX 4600 and SRX 5000 Series allows an adjacent attacker to cause a Denial of Service (DoS). If an SRX is configured in L2 transparent 0.3% —
CVE-2023-36833 MED 6.5 juniper junos_os_evolved A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36MR, and PTX10004, PTX10008, PTX10016 with LC1201/1202 allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). The 0.3% —
CVE-2023-36799 MED 6.5 microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability 4.9% —
CVE-2023-36761 MED 6.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 19.6%