57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-52497 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, that was used to handle the cases that some pages of compressed data are act | 0.3% | — |
| CVE-2023-52453 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume When the optional PRE_COPY support was added to speed up the device compatibility check, it failed to update the s | 0.2% | — |
| CVE-2023-51747 | HIGH 7.1 | apache james Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SM | 1.0% | — |
| CVE-2023-48676 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943. | 0.2% | — |
| CVE-2023-45247 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 391 | 0.2% | — |
| CVE-2023-45246 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 391 | 0.2% | — |
| CVE-2023-45244 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 373 | 0.2% | — |
| CVE-2023-44212 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 31477. | 0.2% | — |
| CVE-2023-44211 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 31637, Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | 0.2% | — |
| CVE-2023-4387 | HIGH 7.1 | linux linux_kernel A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxn | 0.2% | — |
| CVE-2023-41838 | HIGH 7.1 | fortinet fortianalyzer An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli. | 0.5% | — |
| CVE-2023-41673 | HIGH 7.1 | fortinet fortiadc An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests. | 0.4% | — |
| CVE-2023-40720 | HIGH 7.1 | fortinet fortivoice An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests. | 0.8% | — |
| CVE-2023-38402 | HIGH 7.1 | hp aruba_virtual_intranet_access A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) conditi | 0.2% | — |
| CVE-2023-36876 | HIGH 7.1 | microsoft windows_server_2008 Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-36860 | HIGH 7.1 | intel unison_software Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0.7% | — |
| CVE-2023-36858 | HIGH 7.1 | f5 access_policy_manager_clients An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate | 0.1% | — |
| CVE-2023-36635 | HIGH 7.1 | fortinet fortiswitchmanager An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. | 0.5% | — |
| CVE-2023-36634 | HIGH 7.1 | fortinet fortiap-u An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbi | 0.6% | — |
| CVE-2023-36562 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36399 | HIGH 7.1 | microsoft windows_11_21h2 Windows Storage Elevation of Privilege Vulnerability | 8.3% | — |
| CVE-2023-36046 | HIGH 7.1 | microsoft windows_11_21h2 Windows Authentication Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-36027 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-36024 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-3567 | HIGH 7.1 | canonical ubuntu_linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | 0.4% | — |