IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2023-23389 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0.3%
CVE-2023-23388 HIGH 8.8 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1.6%
CVE-2023-23385 HIGH 7.0 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability 0.3%
CVE-2023-23384 HIGH 7.3 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 0.9%
CVE-2023-23383 HIGH 8.2 microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability 11.7%
CVE-2023-23382 MED 6.5 microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability 2.7%
CVE-2023-23381 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.4%
CVE-2023-23379 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 0.4%
CVE-2023-23378 HIGH 7.8 microsoft print_3d Print 3D Remote Code Execution Vulnerability 0.7%
CVE-2023-23377 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-23375 HIGH 7.8 microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability 0.7%
CVE-2023-23374 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.1%
CVE-2023-23208 MED 6.1 genesys administrator_extension Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. 0.4%
CVE-2023-2318 HIGH 8.6 marktext marktext DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a m 0.5%
CVE-2023-2317 HIGH 8.6 typora typora DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vul 2.4%
CVE-2023-2316 HIGH 7.4 typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma 0.7%
CVE-2023-2313 HIGH 8.8 google chrome Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) 0.7%
CVE-2023-23039 MED 5.7 linux linux_kernel An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_rem 0.2%
CVE-2023-23006 MED 5.5 linux linux_kernel In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer). 0.2%
CVE-2023-23005 MED 5.5 linux linux_kernel In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases 0.3%
CVE-2023-23004 MED 5.5 linux linux_kernel In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer). 0.3%
CVE-2023-23003 MED 4.0 linux linux_kernel In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value. 0.3%
CVE-2023-23002 MED 5.5 linux linux_kernel In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer). 0.2%
CVE-2023-23001 MED 5.5 linux linux_kernel In the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case, whereas it is actually an error pointer). 0.2%
CVE-2023-23000 MED 5.5 linux linux_kernel In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the error case, but an error pointer is used. 0.3%