56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-38152 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 24.0% | — |
| CVE-2023-37401 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. | 0.2% | — |
| CVE-2023-37244 | MED 5.3 | n-able automation_manager The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attack | 0.2% | — |
| CVE-2023-36851 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph | 1.1% | |
| CVE-2023-36847 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php | 85.8% | |
| CVE-2023-36846 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't | 95.1% | |
| CVE-2023-36844 | MED 5.3 | juniper junos A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify | 91.4% | |
| CVE-2023-36801 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 1.5% | — |
| CVE-2023-36012 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-35906 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649. | 0.3% | — |
| CVE-2023-35619 | MED 5.3 | microsoft office_long_term_servicing_channel Microsoft Outlook for Mac Spoofing Vulnerability | 1.2% | — |
| CVE-2023-35373 | MED 5.3 | microsoft mono Mono Authenticode Validation Spoofing Vulnerability | 0.8% | — |
| CVE-2023-34055 | MED 5.3 | vmware spring_boot In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following | 1.2% | — |
| CVE-2023-34053 | MED 5.3 | vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the appl | 1.1% | — |
| CVE-2023-34040 | MED 5.3 | vmware spring_for_apache_kafka In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deser | 2.1% | — |
| CVE-2023-34038 | MED 5.3 | vmware horizon_client VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration. | 0.5% | — |
| CVE-2023-34037 | MED 5.3 | vmware horizon_client VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. | 0.5% | — |
| CVE-2023-34036 | MED 5.3 | vmware spring_hateoas Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in pla | 0.5% | — |
| CVE-2023-33857 | MED 5.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. | 0.7% | — |
| CVE-2023-33300 | MED 5.3 | fortinet fortinac A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication | 13.7% | — |
| CVE-2023-33008 | MED 5.3 | apache johnzon Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and mayb | 1.5% | — |
| CVE-2023-32553 | MED 5.3 | trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. | 0.5% | — |
| CVE-2023-32552 | MED 5.3 | trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553 | 0.6% | — |
| CVE-2023-32013 | MED 5.3 | microsoft windows_10_1809 Windows Hyper-V Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-30987 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain databases. IBM X-Force ID: 253440. | 0.8% | — |