58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23838 | MED 6.5 | solarwinds database_performance_analyzer Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | 1.3% | — |
| CVE-2023-23775 | MED 6.5 | fortinet fortisoar Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strin | 0.8% | — |
| CVE-2023-23411 | MED 6.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.6% | — |
| CVE-2023-23396 | MED 6.5 | microsoft office_online_server Microsoft Excel Denial of Service Vulnerability | 3.8% | — |
| CVE-2023-23382 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability | 2.7% | — |
| CVE-2023-22888 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is | 1.4% | — |
| CVE-2023-22887 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requi | 1.8% | — |
| CVE-2023-2282 | MED 6.5 | devolutions remote_desktop_manager Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector. | 0.4% | — |
| CVE-2023-22637 | MED 6.5 | fortinet fortinac An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Mana | 0.6% | — |
| CVE-2023-22414 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a heap memory leak and le | 0.3% | — |
| CVE-2023-22407 | MED 6.5 | juniper junos An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). An rpd crash can occur when an MPLS TE tunnel configurat | 0.3% | — |
| CVE-2023-22406 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). In a segment-routing scenario with OSPF as IGP, | 0.3% | — |
| CVE-2023-22405 | MED 6.5 | juniper junos An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS) to devi | 0.3% | — |
| CVE-2023-22404 | MED 6.5 | juniper junos An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS). iked will crash and restart | 0.6% | — |
| CVE-2023-22395 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In an MPLS scenario specific packets destined to an Integrated Routin | 0.3% | — |
| CVE-2023-22392 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). PTX3000, PTX5000, QFX10000, PTX1000, PTX100 | 0.3% | — |
| CVE-2023-22310 | MED 6.5 | intel aptio_v_uefi_firmware_integrator_tools Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | 0.1% | — |
| CVE-2023-22305 | MED 6.5 | intel aptio_v_uefi_firmware_integrator_tools Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-22290 | MED 6.5 | intel unison_software Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-22283 | MED 6.5 | f5 big-ip_access_policy_manager On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the exe | 0.2% | — |
| CVE-2023-22268 | MED 6.5 | adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploit | 1.2% | — |
| CVE-2023-21807 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-21751 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.0% | — |
| CVE-2023-21721 | MED 6.5 | microsoft onenote Microsoft OneNote Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-21719 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.7% | — |