57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-33152 | HIGH 7.0 | microsoft 365_apps Microsoft ActiveX Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2023-32555 | HIGH 7.0 | trendmicro apex_one A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-p | 0.2% | — |
| CVE-2023-32554 | HIGH 7.0 | trendmicro apex_one A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-p | 0.2% | — |
| CVE-2023-32050 | HIGH 7.0 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-32010 | HIGH 7.0 | microsoft windows_11_22h2 Windows Bus Filter Driver Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-29368 | HIGH 7.0 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-29364 | HIGH 7.0 | microsoft windows_10_1507 Windows Authentication Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-29361 | HIGH 7.0 | microsoft windows_10_21h2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 4.0% | — |
| CVE-2023-28466 | HIGH 7.0 | debian debian_linux do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference). | 0.3% | — |
| CVE-2023-28273 | HIGH 7.0 | microsoft windows_10_1607 Windows Clip Service Elevation of Privilege Vulnerability | 0.2% | — |
| CVE-2023-28229 | HIGH 7.0 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2023-28221 | HIGH 7.0 | microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-28218 | HIGH 7.0 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 12.3% | — |
| CVE-2023-28216 | HIGH 7.0 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-27470 | HIGH 7.0 | n-able take_control BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion. | 0.5% | — |
| CVE-2023-25839 | HIGH 7.0 | esri arcgis_insights There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted i | 0.2% | — |
| CVE-2023-24914 | HIGH 7.0 | microsoft windows_11_22h2 Win32k Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-24899 | HIGH 7.0 | microsoft windows_11_21h2 Windows Graphics Component Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-24861 | HIGH 7.0 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23393 | HIGH 7.0 | microsoft windows_10_1809 Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | 0.2% | — |
| CVE-2023-23385 | HIGH 7.0 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-2270 | HIGH 7.0 | netskope netskope The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope client before R100 in this service utilized a relative path to | 0.3% | — |
| CVE-2023-22657 | HIGH 7.0 | f5 f5os-a On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not e | 0.4% | — |
| CVE-2023-22636 | HIGH 7.0 | fortinet fortiweb An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request. | 0.2% | — |
| CVE-2023-21771 | HIGH 7.0 | microsoft windows_10 Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | 0.4% | — |