IT
57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-38364 MED 6.1 ibm cics_tx IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. 0.5%
CVE-2023-38177 MED 6.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 3.4%
CVE-2023-36727 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.9%
CVE-2023-36416 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.8%
CVE-2023-36030 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 Sales Spoofing Vulnerability 0.9%
CVE-2023-31020 MED 6.1 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering. 0.1%
CVE-2023-29345 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 1.2%
CVE-2023-28350 MED 6.1 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. 1.1%
CVE-2023-28314 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7%
CVE-2023-28313 MED 6.1 microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability 0.7%
CVE-2023-28286 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0.6%
CVE-2023-25952 MED 6.1 intel arc_a_graphics Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access. 0.2%
CVE-2023-25841 MED 6.1 esri arcgis_server There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary 0.6%
CVE-2023-24935 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.0%
CVE-2023-24488 MED 6.1 citrix application_delivery_controller Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting 80.9%
CVE-2023-23208 MED 6.1 genesys administrator_extension Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. 0.4%
CVE-2023-22849 MED 6.1 apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multi 1.4%
CVE-2023-22418 MED 6.1 f5 big-ip_access_policy_manager On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows a 0.3%
CVE-2023-22397 MED 6.1 juniper junos_os_evolved An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks Junos OS Evolved PTX10003 Series devices allows an adjacently located attacker who has established certain preco 0.2%
CVE-2023-20884 MED 6.1 vmware cloud_foundation VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive informat 0.3%
CVE-2023-20264 MED 6.1 cisco adaptive_security_appliance_software A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticat 0.4%
CVE-2023-20251 MED 6.1 cisco mobility_express_software A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause memory leaks that could eventually lead to a device reboot. This vulnerability is due to memory leaks caus 0.2%
CVE-2023-20228 MED 6.1 cisco encs_5100_firmware A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due t 0.5%
CVE-2023-20206 MED 6.1 cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affec 0.4%
CVE-2023-20202 MED 6.1 cisco ios_xe A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory 0.2%