IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-34059 HIGH 7.4 debian debian_linux open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs. 0.4%
CVE-2023-31131 HIGH 7.4 vmware greenplum_database Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file wri 0.7%
CVE-2023-28974 HIGH 7.4 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Serie 0.3%
CVE-2023-28352 HIGH 7.4 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been e 0.7%
CVE-2023-28348 HIGH 7.4 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being 0.4%
CVE-2023-24948 HIGH 7.4 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1.0%
CVE-2023-24461 HIGH 7.4 f5 big-ip_access_policy_manager An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.3%
CVE-2023-2316 HIGH 7.4 typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma 0.7%
CVE-2023-21820 HIGH 7.4 microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 0.6%
CVE-2023-21526 HIGH 7.4 microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability 1.1%
CVE-2023-20185 HIGH 7.4 cisco nx-os A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an iss 0.3%
CVE-2023-20169 HIGH 7.4 cisco nx-os A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker 0.3%
CVE-2023-20112 HIGH 7.4 cisco business_150ax_firmware A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 f 0.3%
CVE-2023-20089 HIGH 7.4 cisco nx-os A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an 0.3%
CVE-2023-20067 HIGH 7.4 cisco ios_xe A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is 0.3%
CVE-2022-41042 HIGH 7.4 microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability 2.0%
CVE-2022-40678 HIGH 7.4 fortinet fortinac An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to 0.1%
CVE-2022-30209 HIGH 7.4 microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability 2.5%
CVE-2022-30203 HIGH 7.4 microsoft windows_10 Windows Boot Manager Security Feature Bypass Vulnerability 1.5%
CVE-2022-26913 HIGH 7.4 microsoft windows_10 Windows Authentication Information Disclosure Vulnerability 2.4%
CVE-2022-26071 HIGH 7.4 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Manage 1.1%
CVE-2022-22190 HIGH 7.4 juniper paragon_active_assurance_control_center An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature 1.0%
CVE-2022-22176 HIGH 7.4 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial 0.4%
CVE-2022-22163 HIGH 7.4 juniper junos An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If a device is configured as DHCPv6 local 0.4%
CVE-2022-20945 HIGH 7.4 cisco catalyst_9800-40_firmware A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu 0.4%