IT
56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.807 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-38169 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 1.3%
CVE-2023-38151 HIGH 8.8 microsoft host_integration_server Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability 1.8%
CVE-2023-38148 HIGH 8.8 microsoft windows_10_21h2 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 8.2%
CVE-2023-38147 HIGH 8.8 microsoft windows_10_1507 Windows Miracast Wireless Display Remote Code Execution Vulnerability 1.0%
CVE-2023-38146 HIGH 8.8 microsoft windows_11_21h2 Windows Themes Remote Code Execution Vulnerability 39.5%
CVE-2023-37933 HIGH 8.8 fortinet fortiadc An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTT 0.3%
CVE-2023-37931 HIGH 8.8 fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via se 0.8%
CVE-2023-37415 HIGH 8.8 apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: 1.6%
CVE-2023-36899 HIGH 8.8 microsoft .net_framework ASP.NET Elevation of Privilege Vulnerability 76.7%
CVE-2023-36882 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.4%
CVE-2023-36787 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.0%
CVE-2023-36764 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 2.3%
CVE-2023-3676 HIGH 8.8 kubernetes kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. 12.7%
CVE-2023-36577 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.7%
CVE-2023-36560 HIGH 8.8 microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability 2.9%
CVE-2023-36556 HIGH 8.8 fortinet fortimail An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTP 0.8%
CVE-2023-36549 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req 2.1%
CVE-2023-36542 HIGH 8.8 apache nifi Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution in 1.9%
CVE-2023-36437 HIGH 8.8 microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability 2.0%
CVE-2023-36423 HIGH 8.8 microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability 2.0%
CVE-2023-36419 HIGH 8.8 microsoft azure_hdinsight Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability 1.7%
CVE-2023-36415 HIGH 8.8 microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability 1.6%
CVE-2023-36414 HIGH 8.8 microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability 2.2%
CVE-2023-36402 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2023-36400 HIGH 8.8 microsoft windows_10_1507 Windows HMAC Key Derivation Elevation of Privilege Vulnerability 4.3%