57.574 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.574 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-44175 | MED 6.5 | juniper junos A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (DoS). Continued receip | 0.5% | — |
| CVE-2023-4417 | MED 6.5 | devolutions remote_desktop_manager Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with share | 0.5% | — |
| CVE-2023-44161 | MED 6.5 | acronis cyber_protect Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.2% | — |
| CVE-2023-44160 | MED 6.5 | acronis cyber_protect Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.2% | — |
| CVE-2023-43666 | MED 6.5 | apache inlong Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry | 0.4% | — |
| CVE-2023-42792 | MED 6.5 | apache airflow Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no ac | 1.4% | — |
| CVE-2023-42787 | MED 6.5 | fortinet fortianalyzer A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web consol | 1.4% | — |
| CVE-2023-42786 | MED 6.5 | fortinet fortios A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request. | 0.9% | — |
| CVE-2023-42785 | MED 6.5 | fortinet fortios A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request. | 0.7% | — |
| CVE-2023-42781 | MED 6.5 | apache airflow Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. This is a different issue than CVE-2023-42663 but leading to similar o | 1.7% | — |
| CVE-2023-42780 | MED 6.5 | apache airflow Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of impor | 1.1% | — |
| CVE-2023-42755 | MED 6.5 | debian debian_linux A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to | 0.4% | — |
| CVE-2023-42663 | MED 6.5 | apache airflow Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newe | 1.6% | — |
| CVE-2023-41916 | MED 6.5 | apache linkis In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should | 0.7% | — |
| CVE-2023-41747 | MED 6.5 | acronis cloud_manager Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | 0.4% | — |
| CVE-2023-40712 | MED 6.5 | apache airflow Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be mask | 2.0% | — |
| CVE-2023-40185 | MED 6.5 | shescape_project shescape shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections | 0.7% | — |
| CVE-2023-40037 | MED 6.5 | apache nifi Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass | 2.1% | — |
| CVE-2023-38254 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-38187 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-38157 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2023-38131 | MED 6.5 | intel unison_software Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-37935 | MED 6.5 | fortinet fortios A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET req | 0.9% | — |
| CVE-2023-37932 | MED 6.5 | fortinet fortivoice An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or | 0.6% | — |
| CVE-2023-36913 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 1.7% | — |