57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-22290 | MED 6.5 | intel unison_software Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-22283 | MED 6.5 | f5 big-ip_access_policy_manager On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the exe | 0.2% | — |
| CVE-2023-22268 | MED 6.5 | adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploit | 1.2% | — |
| CVE-2023-21807 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-21751 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.0% | — |
| CVE-2023-21721 | MED 6.5 | microsoft onenote Microsoft OneNote Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-21719 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2023-21703 | MED 6.5 | microsoft azure_data_box_gateway Azure Data Box Gateway Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-21572 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2023-20891 | MED 6.5 | vmware isolation_segment The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system | 0.6% | — |
| CVE-2023-20866 | MED 6.5 | vmware spring_session In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application i | 0.7% | — |
| CVE-2023-20863 | MED 6.5 | vmware spring_framework In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | 1.1% | — |
| CVE-2023-20861 | MED 6.5 | vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | 1.0% | — |
| CVE-2023-20850 | MED 6.5 | google android In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue | 0.1% | — |
| CVE-2023-20849 | MED 6.5 | google android In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: A | 0.1% | — |
| CVE-2023-20848 | MED 6.5 | google android In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue I | 0.1% | — |
| CVE-2023-20842 | MED 6.5 | google android In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue | 0.1% | — |
| CVE-2023-20841 | MED 6.5 | google android In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: A | 0.1% | — |
| CVE-2023-20840 | MED 6.5 | google android In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Is | 0.1% | — |
| CVE-2023-20271 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability i | 0.5% | — |
| CVE-2023-20266 | MED 6.5 | cisco emergency_responder A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to eleva | 0.5% | — |
| CVE-2023-20261 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An | 0.5% | — |
| CVE-2023-20258 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized J | 0.7% | — |
| CVE-2023-20250 | MED 6.5 | cisco rv110w_firmware A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper vali | 0.9% | — |
| CVE-2023-20235 | MED 6.5 | cisco ios_xe A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. | 0.5% | — |