57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-35893 | CRIT 9.9 | ibm security_guardium IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. | 1.4% | — |
| CVE-2023-35887 | MED 5.0 | apache sshd Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" in | 1.3% | — |
| CVE-2023-35845 | MED 4.7 | anaconda anaconda3 Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these fil | 0.1% | — |
| CVE-2023-35838 | MED 5.7 | wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected | 0.7% | — |
| CVE-2023-35829 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. | 0.4% | — |
| CVE-2023-35828 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c. | 0.5% | — |
| CVE-2023-35827 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c. | 0.2% | — |
| CVE-2023-35826 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c. | 0.2% | — |
| CVE-2023-35824 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c. | 0.2% | — |
| CVE-2023-35823 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. | 0.2% | — |
| CVE-2023-35798 | MED 4.3 | apache apache-airflow-providers-microsoft-mssql Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone w | 1.3% | — |
| CVE-2023-35797 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal pa | 2.8% | — |
| CVE-2023-35788 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privileg | 0.5% | — |
| CVE-2023-35701 | MED 6.6 | apache hive Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is r | 1.1% | — |
| CVE-2023-3567 | HIGH 7.1 | canonical ubuntu_linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | 0.4% | — |
| CVE-2023-35644 | HIGH 7.8 | microsoft windows_10_1809 Windows Sysmain Service Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2023-35643 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2023-35642 | MED 6.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.3% | — |
| CVE-2023-35641 | HIGH 8.8 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 7.2% | — |
| CVE-2023-35639 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2023-35638 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 3.3% | — |
| CVE-2023-35636 | MED 6.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 17.7% | — |
| CVE-2023-35635 | MED 5.5 | microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability | 1.0% | — |
| CVE-2023-35634 | HIGH 8.0 | microsoft windows_11_21h2 Windows Bluetooth Driver Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35633 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 8.7% | — |