IT
57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.808 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-21702 HIGH 7.5 microsoft windows_10 Windows iSCSI Service Denial of Service Vulnerability 1.7%
CVE-2023-21701 HIGH 7.5 microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability 1.7%
CVE-2023-21700 HIGH 7.5 microsoft windows_10 Windows iSCSI Discovery Service Denial of Service Vulnerability 1.7%
CVE-2023-21695 HIGH 7.5 microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability 1.0%
CVE-2023-21691 HIGH 7.5 microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability 1.4%
CVE-2023-21683 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0%
CVE-2023-21677 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0%
CVE-2023-2156 HIGH 7.5 debian debian_linux A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remot 6.1%
CVE-2023-21557 HIGH 7.5 microsoft windows_10_1607 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability 2.0%
CVE-2023-21553 HIGH 7.5 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.4%
CVE-2023-21547 HIGH 7.5 microsoft windows_10_1607 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 89.3%
CVE-2023-21539 HIGH 7.5 microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability 1.2%
CVE-2023-21538 HIGH 7.5 fedoraproject fedora .NET Denial of Service Vulnerability 2.7%
CVE-2023-21527 HIGH 7.5 microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability 2.0%
CVE-2023-20899 HIGH 7.5 vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. 0.6%
CVE-2023-20889 HIGH 7.5 vmware vrealize_network_insight Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure. 79.3%
CVE-2023-20883 HIGH 7.5 vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. 0.9%
CVE-2023-20860 HIGH 7.5 vmware spring_framework Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security 3.5%
CVE-2023-20212 HIGH 7.5 cisco secure_endpoint A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An 3.4%
CVE-2023-20197 HIGH 7.5 cisco secure_endpoint A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect c 1.2%
CVE-2023-20155 HIGH 7.5 cisco secure_firewall_management_center A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker wit 0.7%
CVE-2023-20108 HIGH 7.5 cisco unified_communications_manager_im_and_presence_service A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P 0.9%
CVE-2023-20107 HIGH 7.5 cisco adaptive_security_appliance A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and AS 0.7%
CVE-2023-20034 HIGH 7.5 cisco sd-wan Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. 0.6%
CVE-2023-20014 HIGH 7.5 cisco nexus_dashboard A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could 1.0%