IT
56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.807 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-33157 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability 38.2%
CVE-2023-33136 HIGH 8.8 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.7%
CVE-2023-33134 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 2.6%
CVE-2023-33131 HIGH 8.8 microsoft office Microsoft Outlook Remote Code Execution Vulnerability 5.7%
CVE-2023-32336 HIGH 8.8 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. 1.4%
CVE-2023-32200 HIGH 8.8 apache jena There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0. 1.5%
CVE-2023-32049 HIGH 8.8 microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability 4.2%
CVE-2023-32038 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-32031 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 81.5%
CVE-2023-32009 HIGH 8.8 microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability 0.4%
CVE-2023-32007 HIGH 8.8 apache spark ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL 76.0%
CVE-2023-31469 HIGH 8.8 apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by 1.1%
CVE-2023-31038 HIGH 8.8 apache log4cxx SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for SQL injection.  This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx i 1.6%
CVE-2023-3079 HIGH 8.8 apple macos Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 32.1%
CVE-2023-2984 HIGH 8.8 pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. 0.9%
CVE-2023-29373 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-29372 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.3%
CVE-2023-29362 HIGH 8.8 microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability 1.3%
CVE-2023-29330 HIGH 8.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 2.0%
CVE-2023-29328 HIGH 8.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 2.2%
CVE-2023-29181 HIGH 8.8 fortinet fortios A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 thro 0.7%
CVE-2023-28983 HIGH 8.8 juniper junos_os_evolved An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects J 1.5%
CVE-2023-28935 HIGH 8.8 apache unstructured_information_management_architecture ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA 2.8%
CVE-2023-28754 HIGH 8.8 apache shardingsphere Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML c 1.5%
CVE-2023-28737 HIGH 8.8 intel aptio_v_uefi_firmware_integrator_tools Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access. 0.2%