57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-33145 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 8.6% | — |
| CVE-2023-33144 | MED 6.6 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1.3% | — |
| CVE-2023-33143 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-33142 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-33141 | HIGH 7.5 | microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | 2.2% | — |
| CVE-2023-33140 | MED 6.5 | microsoft onenote Microsoft OneNote Spoofing Vulnerability | 1.6% | — |
| CVE-2023-33139 | MED 5.5 | microsoft visual_studio Visual Studio Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-33137 | HIGH 7.8 | microsoft office Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-33136 | HIGH 8.8 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-33135 | HIGH 7.3 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-33134 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-33133 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 44.0% | — |
| CVE-2023-33132 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 0.9% | — |
| CVE-2023-33131 | HIGH 8.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 5.7% | — |
| CVE-2023-33130 | HIGH 7.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2023-33129 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-33128 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-33127 | HIGH 8.1 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2023-33126 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-3312 | HIGH 7.5 | linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. | 0.9% | — |
| CVE-2023-33008 | MED 5.3 | apache johnzon Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and mayb | 1.5% | — |
| CVE-2023-3297 | HIGH 8.1 | canonical accountsservice In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | 0.3% | — |
| CVE-2023-32820 | HIGH 7.5 | google android In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue | 0.4% | — |
| CVE-2023-3282 | MED 6.4 | paloaltonetworks cortex_xsoar A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine. | 0.2% | — |
| CVE-2023-32810 | MED 4.4 | google android In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: | 0.1% | — |