| | CVE-2023-23408 | Microsoft | medium | 4.5 | 2.4%
| | Azure Apache Ambari Spoofing Vulnerability | Mar 14, 2023 | Feb 11, 2026 |
| | CVE-2023-1656 | ForgeRock | high | 7.5 | — | | Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Rem… | Mar 29, 2023 | Apr 14, 2025 |
| | CVE-2023-27533 | Splunk | high | 8.8 | 0.1%
| | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protoc… | Mar 30, 2023 | Feb 13, 2026 |
| | CVE-2018-25084 | ForgeRock | low | 3.5 | — | | A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service A… | Apr 10, 2023 | Nov 21, 2024 |
| | CVE-2022-3748 | ForgeRock | critical | 9.8 | — | | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypas… | Apr 14, 2023 | Nov 21, 2024 |
| | CVE-2022-23721 | ForgeRock | low | 3.8 | — | | PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lea… | Apr 25, 2023 | Nov 21, 2024 |
| | CVE-2022-40722 | ForgeRock | high | 7.7 | — | | A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offl… | Apr 25, 2023 | Nov 21, 2024 |
| | CVE-2022-40723 | ForgeRock | medium | 6.5 | — | | The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA… | Apr 25, 2023 | Nov 21, 2024 |
| | CVE-2022-40724 | ForgeRock | medium | 6.4 | — | | The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site R… | Apr 25, 2023 | Nov 21, 2024 |
| | CVE-2022-40725 | ForgeRock | high | 7.3 | — | | PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be explo… | Apr 25, 2023 | Nov 21, 2024 |
| | CVE-2023-29240 | F5 | medium | 5.4 | 0.1%
| | An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files us… | May 3, 2023 | Jan 27, 2026 |
| | CVE-2023-26210 | Fortinet | high | 7.8 | 0.1%
| | Multiple improper neutralization of special elements used in an os command ('OS Command Injection') … | Jun 13, 2023 | Jan 14, 2026 |
| | CVE-2023-35393 | Microsoft | medium | 4.5 | 0.3%
| | Azure Apache Hive Spoofing Vulnerability | Aug 8, 2023 | Feb 11, 2026 |
| | CVE-2023-35394 | Microsoft | medium | 4.6 | 0.2%
| | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | Aug 8, 2023 | Feb 11, 2026 |
| | CVE-2023-36877 | Microsoft | medium | 4.5 | 0.3%
| | Azure Apache Oozie Spoofing Vulnerability | Aug 8, 2023 | Feb 11, 2026 |
| | CVE-2023-36881 | Microsoft | medium | 4.5 | 0.3%
| | Azure Apache Ambari Spoofing Vulnerability | Aug 8, 2023 | Feb 11, 2026 |
| | CVE-2023-38188 | Microsoft | medium | 4.5 | 0.3%
| | Azure Apache Hadoop Spoofing Vulnerability | Aug 8, 2023 | Feb 11, 2026 |
| | CVE-2023-38156 | Microsoft | high | 7.2 | 0.2%
| | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | Sep 12, 2023 | Feb 11, 2026 |
| | CVE-2023-44487 | Apache | high | 7.5 | 94.4%
| ⚠ KEV | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell… | Oct 10, 2023 | May 12, 2026 |
| | CVE-2023-34992 | Fortinet | critical | 10.0 | 75.9%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Oct 10, 2023 | Jan 14, 2026 |
| | CVE-2023-36419 | Microsoft | high | 8.8 | 0.7%
| | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | Oct 10, 2023 | Feb 11, 2026 |
| | CVE-2023-41680 | Fortinet | high | 7.5 | 0.1%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41681 | Fortinet | high | 7.5 | 0.1%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41682 | Fortinet | high | 8.1 | 0.4%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41836 | Fortinet | low | 3.5 | 0.1%
| | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41843 | Fortinet | high | 7.5 | 0.2%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-34085 | ForgeRock | low | 2.6 | — | | When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attrib… | Oct 25, 2023 | Nov 21, 2024 |
| | CVE-2023-37283 | ForgeRock | high | 8.1 | — | | Under a very specific and highly unrecommended configuration, authentication bypass is possible in t… | Oct 25, 2023 | Nov 21, 2024 |
| | CVE-2023-39219 | ForgeRock | high | 7.5 | — | | PingFederate Administrative Console dependency contains a weakness where console becomes unresponsiv… | Oct 25, 2023 | Nov 21, 2024 |
| | CVE-2023-39231 | ForgeRock | high | 7.3 | — | | PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring se… | Oct 25, 2023 | Nov 21, 2024 |
| | CVE-2023-39930 | ForgeRock | high | 7.5 | — | | A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV… | Oct 25, 2023 | Nov 21, 2024 |
| | CVE-2023-38547 | Veeam | critical | 9.8 | — | | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server… | Nov 7, 2023 | Mar 6, 2025 |
| | CVE-2023-38548 | Veeam | medium | 4.3 | — | | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client … | Nov 7, 2023 | Mar 6, 2025 |
| | CVE-2023-38549 | Veeam | medium | 5.4 | — | | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client … | Nov 7, 2023 | Nov 21, 2024 |
| | CVE-2023-41723 | Veeam | medium | 4.3 | — | | A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashbo… | Nov 7, 2023 | Nov 21, 2024 |
| | CVE-2023-36424 | Microsoft | high | 7.8 | 10.3%
| ⚠ KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Nov 14, 2023 | Apr 14, 2026 |
| | CVE-2023-41844 | Fortinet | low | 3.5 | 0.4%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Dec 13, 2023 | Jan 14, 2026 |
| | CVE-2023-45587 | Fortinet | low | 3.5 | 0.4%
| | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Dec 13, 2023 | Jan 14, 2026 |
| | CVE-2023-48795 | Apache | medium | 5.9 | 53.6%
| | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr… | Dec 18, 2023 | May 12, 2026 |
| | CVE-2023-36496 | ForgeRock | high | 7.7 | — | | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated u… | Feb 1, 2024 | Nov 21, 2024 |
| | CVE-2024-23108 | Fortinet | critical | 10.0 | 90.4%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2024-23109 | Fortinet | critical | 10.0 | 7.0%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2023-40545 | ForgeRock | high | 8.8 | — | | Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method … | Feb 6, 2024 | Nov 21, 2024 |
| | CVE-2024-22021 | Veeam | medium | 4.3 | — | | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (P… | Feb 7, 2024 | Jun 5, 2025 |
| | CVE-2024-22022 | Veeam | high | 8.8 | — | | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-… | Feb 7, 2024 | Jun 3, 2025 |
| | CVE-2024-0590 | Microsoft | medium | 6.1 | 24.8%
| | The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… | Feb 29, 2024 | Apr 8, 2026 |
| | CVE-2023-41842 | Fortinet | medium | 6.7 | 0.1%
| | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo… | Mar 12, 2024 | Jan 14, 2026 |
| | CVE-2023-0582 | ForgeRock | high | 8.1 | — | | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Forg… | Mar 27, 2024 | Apr 14, 2025 |
| | CVE-2023-47540 | Fortinet | medium | 6.7 | 0.1%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2023-47541 | Fortinet | medium | 6.7 | 0.1%
| | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F… | Apr 9, 2024 | Jan 14, 2026 |