57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-32012 | HIGH 7.8 | microsoft windows_10_21h2 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-32011 | HIGH 7.5 | microsoft windows_10_1507 Windows iSCSI Discovery Service Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-32010 | HIGH 7.0 | microsoft windows_11_22h2 Windows Bus Filter Driver Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-32009 | HIGH 8.8 | microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-32008 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-32007 | HIGH 8.8 | apache spark ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL | 76.0% | — |
| CVE-2023-3181 | HIGH 7.8 | splashtop mirroring360_receiver The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system rebo | 0.2% | — |
| CVE-2023-3161 | MED 5.5 | fedoraproject fedora A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible | 0.2% | — |
| CVE-2023-3159 | MED 6.7 | linux linux_kernel A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails. | 0.2% | — |
| CVE-2023-31488 | CRIT 9.8 | cisco ironport_email_security_appliance Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbit | 0.7% | — |
| CVE-2023-31469 | HIGH 8.8 | apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by | 1.1% | — |
| CVE-2023-31454 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. Users are advi | 1.2% | — |
| CVE-2023-31453 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the del | 1.2% | — |
| CVE-2023-31436 | HIGH 7.8 | linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. | 0.6% | — |
| CVE-2023-3141 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | 0.4% | — |
| CVE-2023-31248 | HIGH 7.8 | canonical ubuntu_linux Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace | 2.1% | — |
| CVE-2023-31206 | HIGH 7.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apac | 1.2% | — |
| CVE-2023-31173 | HIGH 7.7 | selinc sel-5037_sel_grid_configurator Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects | 0.2% | — |
| CVE-2023-31167 | MED 5.0 | selinc sel-5036_acselerator_bay_screen_builder Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder Software on Windows allows Relative Path Traversal. SEL acSELerator Bay Screen Builde | 0.4% | — |
| CVE-2023-31132 | HIGH 7.8 | cacti cacti Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files | 0.4% | — |
| CVE-2023-31131 | HIGH 7.4 | vmware greenplum_database Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file wri | 0.7% | — |
| CVE-2023-31122 | HIGH 7.5 | apache http_server Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. | 3.0% | — |
| CVE-2023-3111 | HIGH 7.8 | debian debian_linux A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | 0.4% | — |
| CVE-2023-31103 | HIGH 7.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to A | 1.3% | — |
| CVE-2023-31102 | HIGH 7.8 | 7-zip 7-zip Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | 57.1% | — |