58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36635 | HIGH 7.1 | fortinet fortiswitchmanager An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. | 0.5% | — |
| CVE-2023-36634 | HIGH 7.1 | fortinet fortiap-u An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbi | 0.6% | — |
| CVE-2023-36562 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-36399 | HIGH 7.1 | microsoft windows_11_21h2 Windows Storage Elevation of Privilege Vulnerability | 8.3% | — |
| CVE-2023-36046 | HIGH 7.1 | microsoft windows_11_21h2 Windows Authentication Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-36027 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-36024 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-3567 | HIGH 7.1 | canonical ubuntu_linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | 0.4% | — |
| CVE-2023-35347 | HIGH 7.1 | microsoft windows_10_21h2 Microsoft Install Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-34058 | HIGH 7.1 | debian debian_linux VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target vi | 0.7% | — |
| CVE-2023-34044 | HIGH 7.1 | vmware fusion VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privi | 0.2% | — |
| CVE-2023-3317 | HIGH 7.1 | linux linux_kernel A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi mt76/mt7921 sub-component in the Linux Kernel. This flaw could allow an attacker to crash the system after 'features' memory release. | 0.2% | — |
| CVE-2023-3268 | HIGH 7.1 | debian debian_linux An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information. | 0.5% | — |
| CVE-2023-32021 | HIGH 7.1 | microsoft windows_server_2012 Windows SMB Witness Service Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-3141 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | 0.4% | — |
| CVE-2023-29337 | HIGH 7.1 | microsoft nuget NuGet Client Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-28973 | HIGH 7.1 | juniper junos_os_evolved An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Admini | 0.1% | — |
| CVE-2023-28724 | HIGH 7.1 | f5 nginx_api_connectivity_manager NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Suppo | 0.2% | — |
| CVE-2023-28344 | HIGH 7.1 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. At | 0.9% | — |
| CVE-2023-28224 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-28222 | HIGH 7.1 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-26607 | HIGH 7.1 | linux linux_kernel In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | 0.6% | — |
| CVE-2023-25517 | HIGH 7.1 | nvidia gpu_display_driver NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering. | 0.2% | — |
| CVE-2023-24904 | HIGH 7.1 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-23414 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0.4% | — |