57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-21550 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-21549 | HIGH 8.8 | microsoft windows_10_1607 Windows SMB Witness Service Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2023-21548 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21547 | HIGH 7.5 | microsoft windows_10_1607 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 89.3% | — |
| CVE-2023-21546 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21543 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-21542 | HIGH 7.0 | microsoft windows_10_1607 Windows Installer Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-21541 | HIGH 7.8 | microsoft windows_10_1607 Windows Task Scheduler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21540 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-21539 | HIGH 7.5 | microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-21538 | HIGH 7.5 | fedoraproject fedora .NET Denial of Service Vulnerability | 2.7% | — |
| CVE-2023-21537 | HIGH 7.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-21536 | MED 4.7 | microsoft windows_10_1809 Event Tracing for Windows Information Disclosure Vulnerability | 0.4% | — |
| CVE-2023-21535 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21532 | HIGH 7.0 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-21531 | HIGH 7.0 | microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21528 | HIGH 7.8 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-21527 | HIGH 7.5 | microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21526 | HIGH 7.4 | microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-21525 | MED 5.3 | microsoft windows_10_1607 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.5% | — |
| CVE-2023-21524 | HIGH 7.8 | microsoft windows_10_1607 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-2124 | HIGH 7.8 | debian debian_linux An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. | 0.5% | — |
| CVE-2023-2110 | HIGH 8.2 | obsidian obsidian Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens | 0.4% | — |
| CVE-2023-20900 | HIGH 7.1 | debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that targe | 1.3% | — |
| CVE-2023-20899 | HIGH 7.5 | vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. | 0.6% | — |