58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.007 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21324 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-21322 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2024-20483 | HIGH 7.2 | cisco ios_xr Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or d | 1.1% | — |
| CVE-2024-20470 | HIGH 7.2 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this | 0.6% | — |
| CVE-2024-20404 | HIGH 7.2 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific | 22.6% | — |
| CVE-2024-1882 | HIGH 7.2 | papercut papercut_mf This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server. | 1.4% | — |
| CVE-2024-1654 | HIGH 7.2 | papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo | 1.3% | — |
| CVE-2023-5528 | HIGH 7.2 | fedoraproject fedora A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugi | 4.3% | — |
| CVE-2023-51441 | HIGH 7.2 | apache axis ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects Apache Axis: through 1.3. As Axis 1 has been EOL we recommend you migrate to a di | 1.2% | — |
| CVE-2023-51387 | HIGH 7.2 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are supposed to be some simple expressions. However, due to improper sanitization for alert expressions in version prior | 1.4% | — |
| CVE-2023-49898 | HIGH 7.2 | apache streampark In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful at | 2.3% | — |
| CVE-2023-49328 | HIGH 7.2 | wolterskluwer b.point On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module. | 1.0% | — |
| CVE-2023-46714 | HIGH 7.2 | fortinet fortios A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs | 1.4% | — |
| CVE-2023-46712 | HIGH 7.2 | fortinet fortiportal A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. | 0.7% | — |
| CVE-2023-4551 | HIGH 7.2 | opentext appbuilder Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated u | 1.0% | — |
| CVE-2023-42768 | HIGH 7.2 | f5 big-ip_access_policy_manager When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to | 0.5% | — |
| CVE-2023-41179 | HIGH 7.2 | trendmicro apex_one A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands o | 4.7% | |
| CVE-2023-3864 | HIGH 7.2 | snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 0.6% | — |
| CVE-2023-38167 | HIGH 7.2 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2023-38156 | HIGH 7.2 | microsoft azure_hdinsight Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2023-36789 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2023-36786 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2023-36780 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-36639 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA | 1.1% | — |
| CVE-2023-36401 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability | 1.9% | — |