57.701 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.701 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36431 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36395 | HIGH 7.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36392 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36010 | HIGH 7.5 | microsoft malware_protection_platform Microsoft Defender Denial of Service Vulnerability | 2.7% | — |
| CVE-2023-36005 | HIGH 7.5 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 23.9% | — |
| CVE-2023-36004 | HIGH 7.5 | microsoft windows_10_1507 Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability | 1.4% | — |
| CVE-2023-35643 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2023-35638 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 3.3% | — |
| CVE-2023-35622 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.6% | — |
| CVE-2023-35621 | HIGH 7.5 | microsoft dynamics_365 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | 2.3% | — |
| CVE-2023-35383 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2023-35352 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2023-35339 | HIGH 7.5 | microsoft windows_10_1507 Windows CryptoAPI Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-35338 | HIGH 7.5 | microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-35330 | HIGH 7.5 | microsoft windows_10_1507 Windows Extended Negotiation Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-35325 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Information Disclosure Vulnerability | 1.8% | — |
| CVE-2023-35309 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-35298 | HIGH 7.5 | microsoft windows_11_21h2 HTTP.sys Denial of Service Vulnerability | 1.8% | — |
| CVE-2023-35077 | HIGH 7.5 | ivanti endpoint_manager An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. | 2.2% | — |
| CVE-2023-34984 | HIGH 7.5 | fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | 0.7% | — |
| CVE-2023-34981 | HIGH 7.5 | apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m | 1.1% | — |
| CVE-2023-34434 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are adv | 1.7% | — |
| CVE-2023-33933 | HIGH 7.5 | apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users shou | 1.5% | — |
| CVE-2023-33850 | HIGH 7.5 | ibm cics_tx IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulne | 1.2% | — |
| CVE-2023-33163 | HIGH 7.5 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.4% | — |