57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-0136 | HIGH 7.6 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit i | 0.7% | — |
| CVE-2024-0135 | HIGH 7.6 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of | 1.1% | — |
| CVE-2023-5808 | HIGH 7.6 | hitachi vantara_hitachi_network_attached_storage SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be bar | 0.5% | — |
| CVE-2023-44313 | HIGH 7.6 | apache servicecomb Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). Users are recommended to u | 3.5% | — |
| CVE-2023-38164 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36886 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36800 | HIGH 7.6 | microsoft dynamics_365 Dynamics Finance and Operations Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-36410 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36049 | HIGH 7.6 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 12.5% | — |
| CVE-2023-36031 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36020 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2023-36007 | HIGH 7.6 | microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | 1.1% | — |
| CVE-2023-32022 | HIGH 7.6 | microsoft windows_server_2012 Windows Server Service Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2023-30469 | HIGH 7.6 | hitachi ops_center_analyzer Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00. | 0.4% | — |
| CVE-2023-28309 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2022-39946 | HIGH 7.6 | fortinet fortinac An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative int | 0.7% | — |
| CVE-2022-21932 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | 1.1% | — |
| CVE-2022-21891 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 1.5% | — |
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2021-41372 | HIGH 7.6 | microsoft power_bi_report_server A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulne | 0.7% | — |
| CVE-2021-40484 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-40483 | HIGH 7.6 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-38652 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2021-38651 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2021-38650 | HIGH 7.6 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1.6% | — |