IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.831 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-21798 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-21797 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-21744 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 2.8%
CVE-2023-21742 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 55.8%
CVE-2023-21732 HIGH 8.8 microsoft windows_10_1607 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.4%
CVE-2023-21727 HIGH 8.8 microsoft windows_10_1607 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.6%
CVE-2023-21717 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 1.1%
CVE-2023-21713 HIGH 8.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2023-21707 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 82.0%
CVE-2023-21706 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 4.1%
CVE-2023-21705 HIGH 8.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.1%
CVE-2023-21686 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.1%
CVE-2023-21685 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.2%
CVE-2023-21684 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-21681 HIGH 8.8 microsoft windows_10_1607 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.4%
CVE-2023-21676 HIGH 8.8 microsoft windows_10_1809 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.5%
CVE-2023-21674 HIGH 8.8 microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 41.8%
CVE-2023-21549 HIGH 8.8 microsoft windows_10_1607 Windows SMB Witness Service Elevation of Privilege Vulnerability 1.4%
CVE-2023-21529 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 62.1%
CVE-2023-20888 HIGH 8.8 vmware vrealize_network_insight Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in 82.3%
CVE-2023-20886 HIGH 8.8 vmware workspace_one_uem VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user. 0.4%
CVE-2023-20877 HIGH 8.8 vmware cloud_foundation VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. 0.7%
CVE-2023-20872 HIGH 8.8 vmware fusion VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. 0.9%
CVE-2023-20856 HIGH 8.8 vmware vrealize_operations VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. 0.4%
CVE-2023-20855 HIGH 8.8 vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen 1.3%