57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2023-27497 | CRIT 10.0 | sap diagnostics_agent Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation | 0.8% | — |
| CVE-2023-27470 | HIGH 7.0 | n-able take_control BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion. | 0.5% | — |
| CVE-2023-27382 | MED 6.7 | intel nuc_p14e_laptop_element Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.1% | — |
| CVE-2023-27378 | HIGH 7.5 | f5 big-ip_access_policy_manager Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached | 0.4% | — |
| CVE-2023-2737 | MED 5.7 | thalesgroup safenet_authentication_service Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation. | 0.1% | — |
| CVE-2023-27366 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 0.5% | — |
| CVE-2023-27365 | HIGH 7.8 | foxit pdf_editor Foxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vul | 0.5% | — |
| CVE-2023-27364 | HIGH 7.8 | foxit pdf_editor Foxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vul | 0.5% | — |
| CVE-2023-27363 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulner | 47.0% | — |
| CVE-2023-27331 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 3.9% | — |
| CVE-2023-27330 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i | 3.9% | — |
| CVE-2023-27329 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 3.9% | — |
| CVE-2023-27305 | MED 6.7 | intel arc_a_graphics Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-27296 | HIGH 8.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 th | 1.5% | — |
| CVE-2023-27272 | LOW 3.1 | ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. | 0.3% | — |
| CVE-2023-2679 | MED 4.1 | snowsoftware snow_license_manager Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. | 0.4% | — |
| CVE-2023-26607 | HIGH 7.1 | linux linux_kernel In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | 0.6% | — |
| CVE-2023-26606 | HIGH 7.8 | linux linux_kernel In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c. | 0.4% | — |
| CVE-2023-26605 | HIGH 7.8 | linux linux_kernel In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid. | 0.4% | — |
| CVE-2023-26589 | MED 6.5 | intel aptio_v_uefi_firmware_integrator_tools Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-26545 | MED 4.7 | debian debian_linux In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. | 0.3% | — |
| CVE-2023-26544 | HIGH 7.8 | linux linux_kernel In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size. | 0.4% | — |
| CVE-2023-26513 | HIGH 7.5 | apache sling_resource_merger Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. | 1.5% | — |
| CVE-2023-26512 | CRIT 9.8 | apache eventmesh-connector-rabbitmq CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. | 1.4% | — |
| CVE-2023-26464 | HIGH 7.5 | apache log4j ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on w | 1.9% | — |