57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2023-3006 | MED 5.5 | linux linux_kernel A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU B | 0.3% | — |
| CVE-2023-2985 | MED 5.5 | linux linux_kernel A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause a denial of service problem. | 0.2% | — |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0.9% | — |
| CVE-2023-2971 | MED 6.3 | typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo | 0.5% | — |
| CVE-2023-29542 | CRIT 9.8 | mozilla firefox A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox an | 0.9% | — |
| CVE-2023-29532 | MED 5.5 | mozilla firefox A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-l | 0.2% | — |
| CVE-2023-29487 | CRIT 9.1 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is | 0.7% | — |
| CVE-2023-29486 | CRIT 9.8 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that t | 1.0% | — |
| CVE-2023-29485 | CRIT 9.8 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention modul | 1.0% | — |
| CVE-2023-29413 | HIGH 7.5 | schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. | 0.7% | — |
| CVE-2023-29412 | CRIT 9.8 | schneider-electric apc_easy_ups_online_monitoring_software CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface. | 1.2% | — |
| CVE-2023-29411 | CRIT 9.8 | schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. | 1.3% | — |
| CVE-2023-2939 | HIGH 7.8 | google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) | 0.5% | — |
| CVE-2023-29373 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29372 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29371 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 5.4% | — |
| CVE-2023-29370 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29369 | MED 6.5 | microsoft windows_server_2012 Remote Procedure Call Runtime Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-29368 | HIGH 7.0 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-29367 | HIGH 7.8 | microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29366 | HIGH 7.8 | microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29365 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29364 | HIGH 7.0 | microsoft windows_10_1507 Windows Authentication Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-29363 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2023-29362 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.3% | — |