IT
58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.007 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-35350 HIGH 7.2 microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability 1.2%
CVE-2023-33234 HIGH 7.2 apache apache-airflow-providers-cncf-kubernetes Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to 1.5%
CVE-2023-29257 HIGH 7.2 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM 1.5%
CVE-2023-29246 HIGH 7.2 apache openmeetings An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 1.5%
CVE-2023-28971 HIGH 7.2 juniper paragon_active_assurance An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to 0.4%
CVE-2023-28742 HIGH 7.2 f5 big-ip_domain_name_system When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 1.5%
CVE-2023-28254 HIGH 7.2 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1.4%
CVE-2023-27995 HIGH 7.2 fortinet fortisoar A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload. 1.1%
CVE-2023-24955 HIGH 7.2 ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 85.4%
CVE-2023-23777 HIGH 7.2 fortinet fortiweb An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash comma 1.3%
CVE-2023-23400 HIGH 7.2 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 1.3%
CVE-2023-22273 HIGH 7.2 adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this is 1.9%
CVE-2023-21710 HIGH 7.2 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 7.9%
CVE-2023-20890 HIGH 7.2 vmware aria_operations_for_networks Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution. 20.2%
CVE-2023-20878 HIGH 7.2 vmware cloud_foundation VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. 1.0%
CVE-2023-20865 HIGH 7.2 vmware aria_operations_for_logs VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. 1.6%
CVE-2023-20858 HIGH 7.2 vmware carbon_black_app_control VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted inp 16.9%
CVE-2023-20273 HIGH 7.2 cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabilit 89.6%
CVE-2023-20254 HIGH 7.2 cisco sd-wan_manager A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vul 0.6%
CVE-2023-20220 HIGH 7.2 cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, 1.1%
CVE-2023-20219 HIGH 7.2 cisco secure_firewall_management_center Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device cr 0.9%
CVE-2023-20128 HIGH 7.2 cisco rv320_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an 30.4%
CVE-2023-20117 HIGH 7.2 cisco rv320_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an 30.4%
CVE-2023-20076 HIGH 7.2 cisco 807_industrial_integrated_services_router_firmware A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters tha 1.5%
CVE-2023-0575 HIGH 7.2 yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula 0.8%