IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2023-36017 HIGH 8.8 microsoft windows_10_1507 Windows Scripting Engine Memory Corruption Vulnerability 25.3%
CVE-2023-36016 MED 6.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.3%
CVE-2023-36014 HIGH 7.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.4%
CVE-2023-36013 MED 6.5 microsoft powershell PowerShell Information Disclosure Vulnerability 1.4%
CVE-2023-36012 MED 5.3 microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability 2.0%
CVE-2023-36011 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0.7%
CVE-2023-36010 HIGH 7.5 microsoft malware_protection_platform Microsoft Defender Denial of Service Vulnerability 2.7%
CVE-2023-36009 MED 5.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 1.2%
CVE-2023-36008 MED 6.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.6%
CVE-2023-36007 HIGH 7.6 microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability 1.1%
CVE-2023-36006 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2023-36005 HIGH 7.5 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 23.9%
CVE-2023-36004 HIGH 7.5 microsoft windows_10_1507 Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability 1.4%
CVE-2023-36003 MED 6.7 microsoft windows_10_1507 XAML Diagnostics Elevation of Privilege Vulnerability 2.8%
CVE-2023-35908 MED 6.5 apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected 1.0%
CVE-2023-35906 MED 5.3 ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649. 0.4%
CVE-2023-35901 LOW 2.7 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380. 0.5%
CVE-2023-35900 MED 4.3 ibm robotic_process_automation IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 25936 0.5%
CVE-2023-35898 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. 0.5%
CVE-2023-35896 MED 5.4 ibm content_navigator IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 0.3%
CVE-2023-35893 CRIT 9.9 ibm security_guardium IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. 1.4%
CVE-2023-35887 MED 5.0 apache sshd Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" in 1.3%
CVE-2023-35845 MED 4.7 anaconda anaconda3 Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these fil 0.1%
CVE-2023-35838 MED 5.7 wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected 0.7%
CVE-2023-35829 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. 0.4%