56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36050 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 39.2% | — |
| CVE-2023-36039 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 73.0% | — |
| CVE-2023-36035 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 86.6% | — |
| CVE-2023-36021 | HIGH 8.0 | microsoft on-prem_data_gateway Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2023-35634 | HIGH 8.0 | microsoft windows_11_21h2 Windows Bluetooth Driver Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35388 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 6.8% | — |
| CVE-2023-3467 | HIGH 8.0 | citrix netscaler_application_delivery_controller Privilege Escalation to root administrator (nsroot) | 1.3% | — |
| CVE-2023-29183 | HIGH 8.0 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6. | 1.1% | — |
| CVE-2023-28310 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 25.0% | — |
| CVE-2023-23780 | HIGH 8.0 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests. | 0.8% | — |
| CVE-2023-21778 | HIGH 8.0 | microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-21762 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.6% | — |
| CVE-2023-21745 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.5% | — |
| CVE-2023-20186 | HIGH 8.0 | cisco ios A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an aff | 0.6% | — |
| CVE-2023-20055 | HIGH 8.0 | cisco catalyst_center A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of se | 0.7% | — |
| CVE-2022-49968 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ieee802154/adf7242: defer destroy_workqueue call There is a possible race condition (use-after-free) like below (FREE) | (USE) adf7242_remove | adf7242 | 0.2% | — |
| CVE-2022-45855 | HIGH 8.0 | apache ambari SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | 1.2% | — |
| CVE-2022-45064 | HIGH 8.0 | apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou | 1.1% | — |
| CVE-2022-42896 | HIGH 8.0 | linux linux_kernel There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could | 2.0% | — |
| CVE-2022-42009 | HIGH 8.0 | apache ambari SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | 1.2% | — |
| CVE-2022-41082 | HIGH 8.0 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2022-41079 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-41078 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-39950 | HIGH 8.0 | fortinet fortianalyzer An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege leve | 0.7% | — |
| CVE-2022-38373 | HIGH 8.0 | fortinet fortideceptor An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests wi | 0.5% | — |