57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-3358 | MED 5.5 | linux linux_kernel A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system. | 0.2% | — |
| CVE-2023-3357 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system. | 0.2% | — |
| CVE-2023-3355 | MED 4.7 | linux linux_kernel A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c code in the submit_lookup_cmds function, which fails because it lacks a check of the return value of kmalloc(). This issue allows a local user to crash the sys | 0.3% | — |
| CVE-2023-3338 | MED 6.5 | debian debian_linux A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. | 8.0% | — |
| CVE-2023-3335 | MED 6.5 | hitachi ops_center_administrator Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00. | 0.2% | — |
| CVE-2023-33308 | CRIT 9.8 | fortinet fortios A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or com | 2.1% | — |
| CVE-2023-33307 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | 0.6% | — |
| CVE-2023-33306 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. | 0.8% | — |
| CVE-2023-33305 | MED 4.9 | fortinet fortios A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2. | 0.8% | — |
| CVE-2023-33304 | MED 4.4 | fortinet forticlient A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials. | 0.2% | — |
| CVE-2023-33303 | HIGH 8.1 | fortinet fortiedr A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request | 0.4% | — |
| CVE-2023-33302 | MED 4.7 | fortinet fortimail A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an aut | 0.4% | — |
| CVE-2023-33301 | MED 6.5 | fortinet fortios An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host. | 0.4% | — |
| CVE-2023-33300 | MED 5.3 | fortinet fortinac A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication | 13.7% | — |
| CVE-2023-33299 | CRIT 9.8 | fortinet fortinac A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note Fo | 24.3% | — |
| CVE-2023-33288 | MED 4.7 | linux linux_kernel An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition. | 0.3% | — |
| CVE-2023-33251 | MED 4.7 | lightbend akka_http When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946. | 0.2% | — |
| CVE-2023-33250 | MED 4.4 | linux linux_kernel The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c. | 0.3% | — |
| CVE-2023-33240 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-defa | 0.2% | — |
| CVE-2023-33234 | HIGH 7.2 | apache apache-airflow-providers-cncf-kubernetes Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to | 1.5% | — |
| CVE-2023-33203 | MED 6.4 | linux linux_kernel The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. | 0.4% | — |
| CVE-2023-33174 | MED 5.5 | microsoft windows_10_1507 Windows Cryptographic Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-33173 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33172 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33171 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |