58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-40185 | MED 6.5 | shescape_project shescape shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections | 0.7% | — |
| CVE-2023-40037 | MED 6.5 | apache nifi Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass | 2.1% | — |
| CVE-2023-38254 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-38187 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-38157 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2023-38131 | MED 6.5 | intel unison_software Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-37935 | MED 6.5 | fortinet fortios A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET req | 0.9% | — |
| CVE-2023-37932 | MED 6.5 | fortinet fortivoice An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or | 0.6% | — |
| CVE-2023-36913 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-36909 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2023-36908 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-36894 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2023-36893 | MED 6.5 | microsoft 365_apps Microsoft Outlook Spoofing Vulnerability | 2.2% | — |
| CVE-2023-36890 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 1.9% | — |
| CVE-2023-36871 | MED 6.5 | microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-36868 | MED 6.5 | microsoft azure_service_fabric Azure Service Fabric on Windows Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-36850 | MED 6.5 | juniper junos An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Management(CFM) module of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an adjacent attacker on the local broadcast | 0.3% | — |
| CVE-2023-36849 | MED 6.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When a malf | 0.3% | — |
| CVE-2023-36848 | MED 6.5 | juniper junos An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Wh | 0.3% | — |
| CVE-2023-36842 | MED 6.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service | 0.3% | — |
| CVE-2023-36839 | MED 6.5 | juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial | 0.3% | — |
| CVE-2023-36834 | MED 6.5 | juniper junos An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX 4600 and SRX 5000 Series allows an adjacent attacker to cause a Denial of Service (DoS). If an SRX is configured in L2 transparent | 0.3% | — |
| CVE-2023-36833 | MED 6.5 | juniper junos_os_evolved A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36MR, and PTX10004, PTX10008, PTX10016 with LC1201/1202 allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). The | 0.3% | — |
| CVE-2023-36799 | MED 6.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2023-36761 | MED 6.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 19.6% |