IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-28267 MED 6.5 microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability 2.1% —
CVE-2023-28158 MED 6.5 apache archiva Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. 1.2% —
CVE-2023-27873 MED 6.5 ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654. 0.8% —
CVE-2023-27859 MED 6.5 ibm db2 IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file 1.0% —
CVE-2023-26589 MED 6.5 intel aptio_v_uefi_firmware_integrator_tools Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access. 0.2% —
CVE-2023-25753 MED 6.5 apache shenyu There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl paramet 0.8% —
CVE-2023-25738 MED 6.5 mozilla firefox Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects 0.6% —
CVE-2023-25621 MED 6.5 apache sling_i18n Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it al 1.1% —
CVE-2023-25606 MED 6.5 fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated att 0.6% —
CVE-2023-24954 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability 1.8% —
CVE-2023-24950 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 67.5% —
CVE-2023-24944 MED 6.5 microsoft windows_10_1809 Windows Bluetooth Driver Information Disclosure Vulnerability 0.7% —
CVE-2023-24938 MED 6.5 microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability 2.0% —
CVE-2023-24937 MED 6.5 microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability 2.1% —
CVE-2023-24922 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1.5% —
CVE-2023-24906 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24890 MED 6.5 microsoft onedrive Microsoft OneDrive for iOS Security Feature Bypass Vulnerability 1.2% —
CVE-2023-24883 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24881 MED 6.5 microsoft teams Microsoft Teams Information Disclosure Vulnerability 1.5% —
CVE-2023-24870 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24866 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24865 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24863 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24857 MED 6.5 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24513 MED 6.5 arista cloudeos On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are 0.7% —