56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.807 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-33157 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 38.2% | — |
| CVE-2023-33136 | HIGH 8.8 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-33134 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-33131 | HIGH 8.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 5.7% | — |
| CVE-2023-32336 | HIGH 8.8 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. | 1.4% | — |
| CVE-2023-32200 | HIGH 8.8 | apache jena There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0. | 1.5% | — |
| CVE-2023-32049 | HIGH 8.8 | microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 4.2% | |
| CVE-2023-32038 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-32031 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 81.5% | — |
| CVE-2023-32009 | HIGH 8.8 | microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-32007 | HIGH 8.8 | apache spark ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL | 76.0% | — |
| CVE-2023-31469 | HIGH 8.8 | apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by | 1.1% | — |
| CVE-2023-31038 | HIGH 8.8 | apache log4cxx SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx i | 1.6% | — |
| CVE-2023-3079 | HIGH 8.8 | apple macos Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 32.1% | |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0.9% | — |
| CVE-2023-29373 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29372 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29362 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-29328 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-29181 | HIGH 8.8 | fortinet fortios A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 thro | 0.7% | — |
| CVE-2023-28983 | HIGH 8.8 | juniper junos_os_evolved An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects J | 1.5% | — |
| CVE-2023-28935 | HIGH 8.8 | apache unstructured_information_management_architecture ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA | 2.8% | — |
| CVE-2023-28754 | HIGH 8.8 | apache shardingsphere Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML c | 1.5% | — |
| CVE-2023-28737 | HIGH 8.8 | intel aptio_v_uefi_firmware_integrator_tools Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |