57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2023-28348 | HIGH 7.4 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being | 0.4% | — |
| CVE-2023-28347 | CRIT 9.6 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabili | 2.8% | — |
| CVE-2023-28346 | HIGH 7.3 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this acce | 0.9% | — |
| CVE-2023-28345 | MED 4.6 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console | 0.3% | — |
| CVE-2023-28344 | HIGH 7.1 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. At | 0.9% | — |
| CVE-2023-28328 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system | 0.2% | — |
| CVE-2023-28327 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a den | 0.2% | — |
| CVE-2023-28326 | CRIT 9.8 | apache openmeetings Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room | 1.3% | — |
| CVE-2023-28314 | MED 6.1 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-28313 | MED 6.1 | microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | 0.7% | — |
| CVE-2023-28312 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Information Disclosure Vulnerability | 1.5% | — |
| CVE-2023-28311 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-28310 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 25.0% | — |
| CVE-2023-28309 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-28308 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28307 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28306 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28305 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28304 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-28303 | LOW 3.3 | microsoft snip_\&_sketch Windows Snipping Tool Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-28302 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 92.6% | — |
| CVE-2023-28301 | LOW 3.7 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 0.9% | — |
| CVE-2023-28300 | HIGH 7.5 | microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2023-28299 | MED 5.5 | microsoft visual_studio_2017 Visual Studio Spoofing Vulnerability | 0.5% | — |
| CVE-2023-28298 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Denial of Service Vulnerability | 0.6% | — |