| | CVE-2023-38547 | Veeam | critical | 9.8 | — | | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server… | Nov 7, 2023 | Mar 6, 2025 |
| | CVE-2023-38548 | Veeam | medium | 4.3 | — | | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client … | Nov 7, 2023 | Mar 6, 2025 |
| | CVE-2023-38549 | Veeam | medium | 5.4 | — | | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client … | Nov 7, 2023 | Nov 21, 2024 |
| | CVE-2023-41723 | Veeam | medium | 4.3 | — | | A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashbo… | Nov 7, 2023 | Nov 21, 2024 |
| | CVE-2023-36424 | Microsoft | high | 7.8 | 10.3%
| ⚠ KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Nov 14, 2023 | Apr 14, 2026 |
| | CVE-2023-20275 | Cisco | medium | 4.1 | 0.4%
| | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar… | Dec 12, 2023 | Aug 11, 2026 |
| | CVE-2023-36009 | Microsoft | medium | 5.5 | 0.2%
| | Microsoft Word Information Disclosure Vulnerability | Dec 12, 2023 | May 19, 2026 |
| | CVE-2023-45587 | Fortinet | low | 3.4 | 0.4%
| | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Dec 13, 2023 | Jul 8, 2026 |
| | CVE-2023-41844 | Fortinet | low | 3.5 | 0.4%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Dec 13, 2023 | Jan 14, 2026 |
| | CVE-2023-48795 | Apache | medium | 5.9 | 53.6%
| | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr… | Dec 18, 2023 | May 12, 2026 |
| | CVE-2020-17163 | Microsoft | high | 7.8 | 0.6%
| | Visual Studio Code Python Extension Remote Code Execution Vulnerability | Dec 29, 2023 | Aug 19, 2026 |
| | CVE-2023-51702 | Apache | medium | 6.5 | 0.4%
| | Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for… | Jan 24, 2024 | Jul 2, 2026 |
| | CVE-2023-36496 | ForgeRock | high | 7.7 | — | | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated u… | Feb 1, 2024 | Nov 21, 2024 |
| | CVE-2024-21399 | Microsoft | high | 8.3 | 1.2%
| | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Feb 2, 2024 | Aug 10, 2026 |
| | CVE-2024-23108 | Fortinet | critical | 10.0 | 90.4%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2024-23109 | Fortinet | critical | 10.0 | 7.0%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2023-40545 | ForgeRock | high | 8.8 | — | | Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method … | Feb 6, 2024 | Nov 21, 2024 |
| | CVE-2024-22021 | Veeam | medium | 4.3 | — | | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (P… | Feb 7, 2024 | Jun 5, 2025 |
| | CVE-2024-22022 | Veeam | high | 8.8 | — | | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-… | Feb 7, 2024 | Jun 3, 2025 |
| | CVE-2024-21762 | Fortinet | critical | 9.8 | 84.3%
| ⚠ KEV | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 t… | Feb 9, 2024 | Aug 4, 2026 |
| | CVE-2024-21338 | Microsoft | high | 7.8 | 59.8%
| ⚠ KEV | Windows Kernel Elevation of Privilege Vulnerability | Feb 13, 2024 | Jul 31, 2026 |
| | CVE-2024-20673 | Microsoft | high | 7.8 | 1.2%
| | Microsoft Office Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-20679 | Microsoft | medium | 6.5 | 1.3%
| | Azure Stack Hub Spoofing Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-20695 | Microsoft | medium | 5.7 | 0.6%
| | Skype for Business Information Disclosure Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21315 | Microsoft | high | 7.8 | 0.6%
| | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21327 | Microsoft | high | 7.6 | 1.3%
| | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21328 | Microsoft | high | 7.6 | 1.3%
| | Dynamics 365 Sales Spoofing Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21329 | Microsoft | high | 7.3 | 1.1%
| | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21364 | Microsoft | critical | 9.3 | 0.6%
| | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21374 | Microsoft | medium | 5.0 | 1.0%
| | Microsoft Teams for Android Information Disclosure Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21376 | Microsoft | critical | 9.0 | 1.2%
| | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21378 | Microsoft | high | 8.8 | 11.1%
| | Microsoft Outlook Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21379 | Microsoft | high | 7.8 | 1.7%
| | Microsoft Word Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21380 | Microsoft | high | 8.0 | 1.7%
| | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21381 | Microsoft | medium | 6.8 | 0.4%
| | Microsoft Azure Active Directory B2C Spoofing Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21384 | Microsoft | high | 7.8 | 0.8%
| | Microsoft Office OneNote Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21386 | Microsoft | high | 7.5 | 2.4%
| | .NET Denial of Service Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21389 | Microsoft | high | 7.6 | 1.2%
| | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21393 | Microsoft | high | 7.6 | 1.2%
| | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21394 | Microsoft | high | 7.6 | 1.1%
| | Dynamics 365 Field Service Spoofing Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21395 | Microsoft | high | 8.2 | 1.1%
| | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21396 | Microsoft | high | 7.6 | 1.2%
| | Dynamics 365 Sales Spoofing Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21397 | Microsoft | medium | 5.3 | 0.5%
| | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21401 | Microsoft | critical | 9.8 | 1.5%
| | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21403 | Microsoft | critical | 9.0 | 1.3%
| | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21404 | Microsoft | high | 7.5 | 2.7%
| | .NET Denial of Service Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-21413 | Microsoft | critical | 9.8 | 94.7%
| ⚠ KEV | Microsoft Outlook Remote Code Execution Vulnerability | Feb 13, 2024 | Aug 10, 2026 |
| | CVE-2024-1635 | Apache | high | 7.5 | 4.6%
| | A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly… | Feb 19, 2024 | Aug 4, 2026 |
| | CVE-2024-21423 | Microsoft | medium | 4.8 | 0.6%
| | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Feb 23, 2024 | Aug 10, 2026 |
| | CVE-2024-26188 | Microsoft | medium | 4.3 | 0.8%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Feb 23, 2024 | Aug 10, 2026 |