57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-23394 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-23393 | HIGH 7.0 | microsoft windows_10_1809 Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | 0.2% | — |
| CVE-2023-23392 | CRIT 9.8 | microsoft windows_11_21h2 HTTP Protocol Stack Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0.6% | — |
| CVE-2023-23390 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23389 | MED 6.3 | microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23388 | HIGH 8.8 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2023-23385 | HIGH 7.0 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23384 | HIGH 7.3 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-23383 | HIGH 8.2 | microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability | 11.7% | — |
| CVE-2023-23382 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability | 2.7% | — |
| CVE-2023-23381 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-23379 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-23378 | HIGH 7.8 | microsoft print_3d Print 3D Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23377 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23375 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23374 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-23208 | MED 6.1 | genesys administrator_extension Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. | 0.4% | — |
| CVE-2023-2318 | HIGH 8.6 | marktext marktext DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a m | 0.5% | — |
| CVE-2023-2317 | HIGH 8.6 | typora typora DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vul | 2.4% | — |
| CVE-2023-2316 | HIGH 7.4 | typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma | 0.7% | — |
| CVE-2023-2313 | HIGH 8.8 | google chrome Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) | 0.7% | — |
| CVE-2023-23039 | MED 5.7 | linux linux_kernel An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_rem | 0.2% | — |
| CVE-2023-23006 | MED 5.5 | linux linux_kernel In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer). | 0.2% | — |
| CVE-2023-23005 | MED 5.5 | linux linux_kernel In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases | 0.3% | — |