58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.007 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35350 | HIGH 7.2 | microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-33234 | HIGH 7.2 | apache apache-airflow-providers-cncf-kubernetes Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to | 1.5% | — |
| CVE-2023-29257 | HIGH 7.2 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM | 1.5% | — |
| CVE-2023-29246 | HIGH 7.2 | apache openmeetings An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | 1.5% | — |
| CVE-2023-28971 | HIGH 7.2 | juniper paragon_active_assurance An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to | 0.4% | — |
| CVE-2023-28742 | HIGH 7.2 | f5 big-ip_domain_name_system When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1.5% | — |
| CVE-2023-28254 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-27995 | HIGH 7.2 | fortinet fortisoar A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload. | 1.1% | — |
| CVE-2023-24955 | HIGH 7.2 | ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 85.4% | |
| CVE-2023-23777 | HIGH 7.2 | fortinet fortiweb An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash comma | 1.3% | — |
| CVE-2023-23400 | HIGH 7.2 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-22273 | HIGH 7.2 | adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this is | 1.9% | — |
| CVE-2023-21710 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 7.9% | — |
| CVE-2023-20890 | HIGH 7.2 | vmware aria_operations_for_networks Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution. | 20.2% | — |
| CVE-2023-20878 | HIGH 7.2 | vmware cloud_foundation VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | 1.0% | — |
| CVE-2023-20865 | HIGH 7.2 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. | 1.6% | — |
| CVE-2023-20858 | HIGH 7.2 | vmware carbon_black_app_control VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted inp | 16.9% | — |
| CVE-2023-20273 | HIGH 7.2 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabilit | 89.6% | |
| CVE-2023-20254 | HIGH 7.2 | cisco sd-wan_manager A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vul | 0.6% | — |
| CVE-2023-20220 | HIGH 7.2 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, | 1.1% | — |
| CVE-2023-20219 | HIGH 7.2 | cisco secure_firewall_management_center Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device cr | 0.9% | — |
| CVE-2023-20128 | HIGH 7.2 | cisco rv320_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an | 30.4% | — |
| CVE-2023-20117 | HIGH 7.2 | cisco rv320_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an | 30.4% | — |
| CVE-2023-20076 | HIGH 7.2 | cisco 807_industrial_integrated_services_router_firmware A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters tha | 1.5% | — |
| CVE-2023-0575 | HIGH 7.2 | yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula | 0.8% | — |