57.701 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.701 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-33143 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-33141 | HIGH 7.5 | microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | 2.2% | — |
| CVE-2023-3312 | HIGH 7.5 | linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. | 0.9% | — |
| CVE-2023-32820 | HIGH 7.5 | google android In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue | 0.4% | — |
| CVE-2023-32783 | HIGH 7.5 | zohocorp manageengine_adaudit_plus The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an exp | 3.9% | — |
| CVE-2023-32331 | HIGH 7.5 | ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. | 0.7% | — |
| CVE-2023-32252 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker ca | 4.1% | — |
| CVE-2023-32248 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to ac | 4.1% | — |
| CVE-2023-32247 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage thi | 3.9% | — |
| CVE-2023-32214 | HIGH 7.5 | mozilla firefox Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thund | 0.9% | — |
| CVE-2023-32084 | HIGH 7.5 | microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability | 1.8% | — |
| CVE-2023-32045 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 1.5% | — |
| CVE-2023-32044 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 1.5% | — |
| CVE-2023-32030 | HIGH 7.5 | microsoft .net_framework .NET and Visual Studio Denial of Service Vulnerability | 2.2% | — |
| CVE-2023-32011 | HIGH 7.5 | microsoft windows_10_1507 Windows iSCSI Discovery Service Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-31454 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. Users are advi | 1.2% | — |
| CVE-2023-31453 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the del | 1.2% | — |
| CVE-2023-31206 | HIGH 7.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apac | 1.2% | — |
| CVE-2023-31122 | HIGH 7.5 | apache http_server Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. | 3.0% | — |
| CVE-2023-31103 | HIGH 7.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to A | 1.3% | — |
| CVE-2023-31064 | HIGH 7.5 | apache inlong Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advis | 1.2% | — |
| CVE-2023-31058 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrad | 1.2% | — |
| CVE-2023-31036 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful | 0.9% | — |
| CVE-2023-30995 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. | 0.9% | — |
| CVE-2023-30991 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 254037. | 0.8% | — |