IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-38152 MED 5.3 microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability 24.0%
CVE-2023-37401 MED 5.3 ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. 0.2%
CVE-2023-37244 MED 5.3 n-able automation_manager The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attack 0.2%
CVE-2023-36851 MED 5.3 juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph 1.1%
CVE-2023-36847 MED 5.3 juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php 85.8%
CVE-2023-36846 MED 5.3 juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't 95.1%
CVE-2023-36844 MED 5.3 juniper junos A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify 91.4%
CVE-2023-36801 MED 5.3 microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability 1.5%
CVE-2023-36012 MED 5.3 microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability 2.0%
CVE-2023-35906 MED 5.3 ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649. 0.3%
CVE-2023-35619 MED 5.3 microsoft office_long_term_servicing_channel Microsoft Outlook for Mac Spoofing Vulnerability 1.2%
CVE-2023-35373 MED 5.3 microsoft mono Mono Authenticode Validation Spoofing Vulnerability 0.8%
CVE-2023-34055 MED 5.3 vmware spring_boot In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following 1.2%
CVE-2023-34053 MED 5.3 vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the appl 1.1%
CVE-2023-34040 MED 5.3 vmware spring_for_apache_kafka In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deser 2.1%
CVE-2023-34038 MED 5.3 vmware horizon_client VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration. 0.5%
CVE-2023-34037 MED 5.3 vmware horizon_client VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. 0.5%
CVE-2023-34036 MED 5.3 vmware spring_hateoas Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in pla 0.5%
CVE-2023-33857 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. 0.7%
CVE-2023-33300 MED 5.3 fortinet fortinac A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication 13.7%
CVE-2023-33008 MED 5.3 apache johnzon Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and mayb 1.5%
CVE-2023-32553 MED 5.3 trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. 0.5%
CVE-2023-32552 MED 5.3 trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553 0.6%
CVE-2023-32013 MED 5.3 microsoft windows_10_1809 Windows Hyper-V Denial of Service Vulnerability 1.6%
CVE-2023-30987 MED 5.3 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain databases. IBM X-Force ID: 253440. 0.8%