57.655 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.655 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-38162 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 10.7% | — |
| CVE-2023-38149 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability | 4.5% | — |
| CVE-2023-38138 | HIGH 7.5 | f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End o | 0.4% | — |
| CVE-2023-38039 | HIGH 7.5 | fedoraproject fedora When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server | 58.1% | — |
| CVE-2023-37930 | HIGH 7.5 | fortinet fortios Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted | 0.6% | — |
| CVE-2023-37544 | HIGH 7.5 | apache pulsar Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2 | 1.4% | — |
| CVE-2023-36912 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2023-36884 | HIGH 7.5 | ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability | 98.9% | |
| CVE-2023-36843 | HIGH 7.5 | juniper junos An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby r | 0.5% | — |
| CVE-2023-36841 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service ( | 0.5% | — |
| CVE-2023-36835 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS). If a specific valid IP packet is re | 0.6% | — |
| CVE-2023-36832 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, | 0.6% | — |
| CVE-2023-36831 | HIGH 7.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading | 0.6% | — |
| CVE-2023-36763 | HIGH 7.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 2.1% | — |
| CVE-2023-36720 | HIGH 7.5 | microsoft windows_10_1607 Windows Mixed Reality Developer Tools Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36709 | HIGH 7.5 | microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability | 2.6% | — |
| CVE-2023-36703 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36606 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 67.2% | — |
| CVE-2023-36603 | HIGH 7.5 | microsoft windows_10_1809 Windows TCP/IP Denial of Service Vulnerability | 2.3% | — |
| CVE-2023-36602 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability | 2.3% | — |
| CVE-2023-36596 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-36585 | HIGH 7.5 | microsoft windows_10_1507 Windows upnphost.dll Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36581 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36579 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36567 | HIGH 7.5 | microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability | 2.0% | — |