IT
58.211 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.211 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-20404 HIGH 7.2 cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific 22.6% —
CVE-2024-1882 HIGH 7.2 papercut papercut_mf This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server. 1.4% —
CVE-2024-1654 HIGH 7.2 papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo 1.3% —
CVE-2023-5528 HIGH 7.2 fedoraproject fedora A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugi 4.3% —
CVE-2023-51441 HIGH 7.2 apache axis ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects Apache Axis: through 1.3. As Axis 1 has been EOL we recommend you migrate to a di 1.2% —
CVE-2023-51387 HIGH 7.2 apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are supposed to be some simple expressions. However, due to improper sanitization for alert expressions in version prior 1.4% —
CVE-2023-49898 HIGH 7.2 apache streampark In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful at 2.3% —
CVE-2023-49328 HIGH 7.2 wolterskluwer b.point On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module. 1.0% —
CVE-2023-46714 HIGH 7.2 fortinet fortios A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs 1.4% —
CVE-2023-46712 HIGH 7.2 fortinet fortiportal A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. 0.7% —
CVE-2023-4551 HIGH 7.2 opentext appbuilder Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated u 1.0% —
CVE-2023-42768 HIGH 7.2 f5 big-ip_access_policy_manager When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to 0.5% —
CVE-2023-41179 HIGH 7.2 trendmicro apex_one A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands o 4.5%
CVE-2023-3864 HIGH 7.2 snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. 0.6% —
CVE-2023-38167 HIGH 7.2 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 1.4% —
CVE-2023-38156 HIGH 7.2 microsoft azure_hdinsight Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability 2.0% —
CVE-2023-36789 HIGH 7.2 microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability 2.4% —
CVE-2023-36786 HIGH 7.2 microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability 2.5% —
CVE-2023-36780 HIGH 7.2 microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability 2.6% —
CVE-2023-36639 HIGH 7.2 fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA 1.1% —
CVE-2023-36401 HIGH 7.2 microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability 1.9% —
CVE-2023-35350 HIGH 7.2 microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability 1.2% —
CVE-2023-33234 HIGH 7.2 apache apache-airflow-providers-cncf-kubernetes Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to 1.5% —
CVE-2023-29257 HIGH 7.2 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM 1.5% —
CVE-2023-29246 HIGH 7.2 apache openmeetings An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 1.5% —