56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-24779 | MED 5.0 | apache superset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to una | 0.7% | — |
| CVE-2024-21615 | MED 5.0 | juniper junos An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system. On all Junos OS and Junos OS Evolved platforms, when NETCONF traceoption | 0.2% | — |
| CVE-2024-21448 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-21374 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-20355 | MED 5.0 | cisco adaptive_security_appliance_software A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to success | 0.3% | — |
| CVE-2023-6184 | MED 5.0 | citrix virtual_apps_and_desktops Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | 46.6% | — |
| CVE-2023-52633 | MED 5.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: um: time-travel: fix time corruption In 'basic' time-travel mode (without =inf-cpu or =ext), we still get timer interrupts. These can happen at arbitrary points in time, i.e. while in timer_ | 0.2% | — |
| CVE-2023-46715 | MED 5.0 | fortinet fortios An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of ano | 0.9% | — |
| CVE-2023-45586 | MED 5.0 | fortinet fortios An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7 | 0.3% | — |
| CVE-2023-44254 | MED 5.0 | fortinet fortianalyzer An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTT | 0.5% | — |
| CVE-2023-44253 | MED 5.0 | fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow | 0.7% | — |
| CVE-2023-44201 | MED 5.0 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions. When a user with t | 0.1% | — |
| CVE-2023-43799 | MED 5.0 | altairgraphql altair Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer pr | 0.2% | — |
| CVE-2023-41234 | MED 5.0 | intel power_gadget NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-39411 | MED 5.0 | intel unison_software Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-35887 | MED 5.0 | apache sshd Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" in | 1.3% | — |
| CVE-2023-34050 | MED 5.0 | vmware spring_advanced_message_queuing_protocol In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, w | 1.5% | — |
| CVE-2023-31167 | MED 5.0 | selinc sel-5036_acselerator_bay_screen_builder Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder Software on Windows allows Relative Path Traversal. SEL acSELerator Bay Screen Builde | 0.4% | — |
| CVE-2023-27523 | MED 5.0 | apache superset Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to. | 0.7% | — |
| CVE-2023-23638 | MED 5.0 | apache dubbo A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x | 4.8% | — |
| CVE-2023-21722 | MED 5.0 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 0.9% | — |
| CVE-2023-20269 | MED 5.0 | ransomware cisco adaptive_security_appliance_software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify val | 21.6% | |
| CVE-2023-20256 | MED 5.0 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and | 0.6% | — |
| CVE-2023-20247 | MED 5.0 | cisco adaptive_security_appliance_software A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication | 0.3% | — |
| CVE-2023-20084 | MED 5.0 | cisco secure_endpoint A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various softwa | 0.2% | — |