56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-40723 | HIGH 8.1 | fortinet fortisiem An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and | 0.4% | — |
| CVE-2023-40537 | HIGH 8.1 | f5 big-ip_access_policy_manager An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate | 0.5% | — |
| CVE-2023-40363 | HIGH 8.1 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332. | 0.6% | — |
| CVE-2023-3865 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized | 0.6% | — |
| CVE-2023-38166 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-37379 | HIGH 8.1 | apache airflow Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connect | 2.0% | — |
| CVE-2023-36897 | HIGH 8.1 | microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability | 1.7% | — |
| CVE-2023-36554 | HIGH 8.1 | fortinet fortimanager A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requ | 0.8% | — |
| CVE-2023-35628 | HIGH 8.1 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 92.8% | — |
| CVE-2023-35297 | HIGH 8.1 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-33303 | HIGH 8.1 | fortinet fortiedr A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request | 0.4% | — |
| CVE-2023-33170 | HIGH 8.1 | fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2023-33127 | HIGH 8.1 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2023-3297 | HIGH 8.1 | canonical accountsservice In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | 0.3% | — |
| CVE-2023-32258 | HIGH 8.1 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an obj | 2.5% | — |
| CVE-2023-32257 | HIGH 8.1 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations o | 2.4% | — |
| CVE-2023-29351 | HIGH 8.1 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2023-29325 | HIGH 8.1 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 84.4% | — |
| CVE-2023-29032 | HIGH 8.1 | apache openmeetings An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0 | 1.1% | — |
| CVE-2023-28656 | HIGH 8.1 | f5 nginx_api_connectivity_manager NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2023-28288 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 6.2% | — |
| CVE-2023-28283 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-28268 | HIGH 8.1 | microsoft windows_server_2008 Netlogon RPC Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-28244 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2023-28220 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 15.0% | — |