IT
57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.411 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-24900 MED 5.9 microsoft windows_10_1507 Windows NTLM Security Support Provider Information Disclosure Vulnerability 1.2%
CVE-2023-22870 MED 5.9 ibm aspera_faspex IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121. 0.3%
CVE-2023-22863 MED 5.9 ibm robotic_process_automation IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force I 0.4%
CVE-2023-22663 MED 5.9 intel unison_software Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. 0.5%
CVE-2023-22448 MED 5.9 intel unison_software Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access. 0.5%
CVE-2023-22402 MED 5.9 juniper junos_os_evolved A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp 0.5%
CVE-2023-22372 MED 5.9 f5 big-ip_access_policy_manager In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.2%
CVE-2023-22302 MED 5.9 f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to th 0.5%
CVE-2023-20896 MED 5.9 vmware vcenter_server The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to deni 0.9%
CVE-2023-0400 MED 5.9 trellix data_loss_prevention The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctl 0.4%
CVE-2022-45434 MED 5.9 dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploi 0.7%
CVE-2022-43927 MED 5.9 ibm db2 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671. 0.6%
CVE-2022-43917 MED 5.9 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditio 0.5%
CVE-2022-43851 MED 5.9 ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.2%
CVE-2022-41116 MED 5.9 microsoft windows_7 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability 1.0%
CVE-2022-41090 MED 5.9 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability 1.0%
CVE-2022-38712 MED 5.9 ibm websphere_application_server "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762." 0.5%
CVE-2022-37965 MED 5.9 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability 1.5%
CVE-2022-35747 MED 5.9 microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability 1.7%
CVE-2022-35646 MED 5.9 ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.   0.4%
CVE-2022-34844 MED 5.9 f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclose 0.7%
CVE-2022-34716 MED 5.9 microsoft .net .NET Spoofing Vulnerability 2.3%
CVE-2022-34361 MED 5.9 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 230522. 0.4%
CVE-2022-34351 MED 5.9 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402. 0.4%
CVE-2022-34310 MED 5.9 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229441. 0.5%