57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.588 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35005 | MED 6.5 | apache airflow In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive- | 1.5% | — |
| CVE-2023-34367 | MED 6.5 | microsoft windows_7 Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor | 1.2% | — |
| CVE-2023-34212 | MED 6.5 | apache nifi The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of | 2.4% | — |
| CVE-2023-34189 | MED 6.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate o | 1.3% | — |
| CVE-2023-34150 | MED 6.5 | apache any23 ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage. | 1.5% | — |
| CVE-2023-33861 | MED 6.5 | ibm security_qradar_edr IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client. | 0.2% | — |
| CVE-2023-3338 | MED 6.5 | debian debian_linux A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. | 8.0% | — |
| CVE-2023-3335 | MED 6.5 | hitachi ops_center_administrator Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00. | 0.2% | — |
| CVE-2023-33307 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | 0.6% | — |
| CVE-2023-33306 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. | 0.8% | — |
| CVE-2023-33301 | MED 6.5 | fortinet fortios An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host. | 0.4% | — |
| CVE-2023-33173 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33172 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33169 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33168 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33167 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33166 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33164 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33151 | MED 6.5 | microsoft 365_apps Microsoft Outlook Spoofing Vulnerability | 3.4% | — |
| CVE-2023-33145 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 8.6% | — |
| CVE-2023-33142 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-33140 | MED 6.5 | microsoft onenote Microsoft OneNote Spoofing Vulnerability | 1.6% | — |
| CVE-2023-33129 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-32083 | MED 6.5 | microsoft windows_server_2016 Microsoft Failover Cluster Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-32042 | MED 6.5 | microsoft windows_10_1507 OLE Automation Information Disclosure Vulnerability | 1.3% | — |