IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2023-25071 MED 5.6 intel arc_a_graphics NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access. 0.2%
CVE-2023-25069 HIGH 8.8 trendmicro txone_stellarone TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker 1.0%
CVE-2023-25012 MED 4.6 linux linux_kernel The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long. 0.8%
CVE-2023-24998 HIGH 7.5 apache commons_fileupload Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the 48.8%
CVE-2023-24997 CRIT 9.8 apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl 1.4%
CVE-2023-24977 HIGH 7.5 apache inlong Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 h 1.2%
CVE-2023-24965 MED 5.8 ibm aspera_faspex IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713. 0.5%
CVE-2023-24964 MED 6.2 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. 0.1%
CVE-2023-24960 HIGH 7.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 24 1.4%
CVE-2023-24954 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability 1.8%
CVE-2023-24953 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.7%
CVE-2023-24950 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 67.5%
CVE-2023-24949 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 24.6%
CVE-2023-24948 HIGH 7.4 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1.0%
CVE-2023-24947 HIGH 8.8 microsoft windows_10_1607 Windows Bluetooth Driver Remote Code Execution Vulnerability 0.7%
CVE-2023-24946 HIGH 7.8 microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability 0.4%
CVE-2023-24945 MED 5.5 microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability 0.6%
CVE-2023-24944 MED 6.5 microsoft windows_10_1809 Windows Bluetooth Driver Information Disclosure Vulnerability 0.7%
CVE-2023-24943 CRIT 9.8 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability 4.7%
CVE-2023-24942 HIGH 7.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.9%
CVE-2023-24941 CRIT 9.8 microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability 94.7%
CVE-2023-24940 HIGH 7.5 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability 5.2%
CVE-2023-24939 HIGH 7.5 microsoft windows_10_1507 Server for NFS Denial of Service Vulnerability 4.7%
CVE-2023-24938 MED 6.5 microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability 2.0%
CVE-2023-24937 MED 6.5 microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability 2.1%