IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36635 HIGH 7.1 fortinet fortiswitchmanager An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. 0.5% —
CVE-2023-36634 HIGH 7.1 fortinet fortiap-u An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbi 0.6% —
CVE-2023-36562 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0% —
CVE-2023-36399 HIGH 7.1 microsoft windows_11_21h2 Windows Storage Elevation of Privilege Vulnerability 8.3% —
CVE-2023-36046 HIGH 7.1 microsoft windows_11_21h2 Windows Authentication Denial of Service Vulnerability 0.7% —
CVE-2023-36027 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1% —
CVE-2023-36024 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1% —
CVE-2023-3567 HIGH 7.1 canonical ubuntu_linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. 0.4% —
CVE-2023-35347 HIGH 7.1 microsoft windows_10_21h2 Microsoft Install Service Elevation of Privilege Vulnerability 0.5% —
CVE-2023-34058 HIGH 7.1 debian debian_linux VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target vi 0.7% —
CVE-2023-34044 HIGH 7.1 vmware fusion VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privi 0.2% —
CVE-2023-3317 HIGH 7.1 linux linux_kernel A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi mt76/mt7921 sub-component in the Linux Kernel. This flaw could allow an attacker to crash the system after 'features' memory release. 0.2% —
CVE-2023-3268 HIGH 7.1 debian debian_linux An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information. 0.5% —
CVE-2023-32021 HIGH 7.1 microsoft windows_server_2012 Windows SMB Witness Service Security Feature Bypass Vulnerability 1.2% —
CVE-2023-3141 HIGH 7.1 debian debian_linux A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. 0.4% —
CVE-2023-29337 HIGH 7.1 microsoft nuget NuGet Client Remote Code Execution Vulnerability 1.1% —
CVE-2023-28973 HIGH 7.1 juniper junos_os_evolved An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Admini 0.1% —
CVE-2023-28724 HIGH 7.1 f5 nginx_api_connectivity_manager NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Suppo 0.2% —
CVE-2023-28344 HIGH 7.1 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. At 0.9% —
CVE-2023-28224 HIGH 7.1 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability 0.4% —
CVE-2023-28222 HIGH 7.1 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.7% —
CVE-2023-26607 HIGH 7.1 linux linux_kernel In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. 0.6% —
CVE-2023-25517 HIGH 7.1 nvidia gpu_display_driver NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering. 0.2% —
CVE-2023-24904 HIGH 7.1 microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability 0.6% —
CVE-2023-23414 HIGH 7.1 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability 0.4% —