IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2023-21543 HIGH 8.1 microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability 1.7%
CVE-2023-21542 HIGH 7.0 microsoft windows_10_1607 Windows Installer Elevation of Privilege Vulnerability 0.3%
CVE-2023-21541 HIGH 7.8 microsoft windows_10_1607 Windows Task Scheduler Elevation of Privilege Vulnerability 0.6%
CVE-2023-21540 MED 5.5 microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability 0.6%
CVE-2023-21539 HIGH 7.5 microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability 1.2%
CVE-2023-21538 HIGH 7.5 fedoraproject fedora .NET Denial of Service Vulnerability 2.7%
CVE-2023-21537 HIGH 7.8 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability 0.5%
CVE-2023-21536 MED 4.7 microsoft windows_10_1809 Event Tracing for Windows Information Disclosure Vulnerability 0.4%
CVE-2023-21535 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2023-21532 HIGH 7.0 microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability 0.4%
CVE-2023-21531 HIGH 7.0 microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability 0.6%
CVE-2023-21528 HIGH 7.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 0.4%
CVE-2023-21527 HIGH 7.5 microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability 2.0%
CVE-2023-21526 HIGH 7.4 microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability 1.1%
CVE-2023-21525 MED 5.3 microsoft windows_10_1607 Remote Procedure Call Runtime Denial of Service Vulnerability 1.5%
CVE-2023-21524 HIGH 7.8 microsoft windows_10_1607 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.4%
CVE-2023-2124 HIGH 7.8 debian debian_linux An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. 0.5%
CVE-2023-2110 HIGH 8.2 obsidian obsidian Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens 0.4%
CVE-2023-20900 HIGH 7.1 debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that targe 1.3%
CVE-2023-20899 HIGH 7.5 vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. 0.6%
CVE-2023-20896 MED 5.9 vmware vcenter_server The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to deni 0.9%
CVE-2023-20895 HIGH 8.1 vmware vcenter_server The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication. 1.4%
CVE-2023-20894 HIGH 8.1 vmware vcenter_server The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to mem 33.9%
CVE-2023-20893 HIGH 8.1 vmware vcenter_server The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hos 1.2%
CVE-2023-20892 HIGH 8.1 vmware vcenter_server The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrar 1.8%