58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36575 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36574 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36573 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36572 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36571 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36570 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36561 | HIGH 7.3 | microsoft azure_devops_server Azure DevOps Server Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36034 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-36014 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-35624 | HIGH 7.3 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-34035 | HIGH 7.3 | vmware spring_security Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s Dispatcher | 0.7% | — |
| CVE-2023-33135 | HIGH 7.3 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-33130 | HIGH 7.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2023-33128 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-33126 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-32054 | HIGH 7.3 | microsoft windows_10_1507 Volume Shadow Copy Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-31016 | HIGH 7.3 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or | 0.2% | — |
| CVE-2023-28346 | HIGH 7.3 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this acce | 0.9% | — |
| CVE-2023-23384 | HIGH 7.3 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-22947 | HIGH 7.3 | shibboleth service_provider Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the ins | 0.3% | — |
| CVE-2023-22635 | HIGH 7.3 | fortinet forticlient A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions | 0.1% | — |
| CVE-2023-22292 | HIGH 7.3 | intel unison_software Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-22282 | HIGH 7.3 | elecom wab-mat WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privileg | 0.2% | — |
| CVE-2023-21715 | HIGH 7.3 | microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability | 12.0% | |
| CVE-2023-21568 | HIGH 7.3 | microsoft sql_server_2019_integration_services Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | 0.9% | — |